RE: [PHP] how to not send plaintext when using mysql_connect -- REPOST
| From: | Carsten H. Pedersen | Date: | Fri, 27 Oct 2000 16:29:46 +0000 |
| Subject: | RE: [PHP] how to not send plaintext when using mysql_connect -- REPOST | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-22347@lists.php.net to get a copy of this message | ||
> From: Daevid Vincent [mailto:DayWalker@TheMatrix.com]
> Subject: RE: [PHP] how to not send plaintext when using mysql_connect --
>
> perhaps I wasn't clear enough.
>
> mysql has a line like
> $linkid = mysql_pconnect( "mysql.mydomain.com", "myuser",
> "mypass") or
> die( "Unable to connect to mySQL server");
>
> the "myuser" and "mypass" are sent in plaintext across the internet to the
> mySQL server "mysql.mydomain.com".
>
> THAT is what is the problem. Those packets can be sniffed by anyone on the
> internet that they happen to go through. hence that user can get
> myuser and
> mypass and write their own PHP page to muck around in my database.
>
> to compound the issue, mySQL REQUIRES the myuser and mypass to be IN
> plaintext from what I understand, so I can't even do something like this:
>
> $linkid = mysql_pconnect( "mysql.mydomain.com", "myuser",
> password("mypass")) or die( "Unable to connect to mySQL server");
>
> or md5() or crypt() or any other form of obfuscation/encryption.
errr.. what would be the point of having the option of sending
an obfuscated password if you're afraid of packet sniffers? Those
sniffers can simply grab the obfuscated password and re-use it,
without even having to know the original password.
/ Carsten
--
Carsten H. Pedersen
keeper and maintainer of the bitbybit.dk MySQL FAQ
http://www.bitbybit.dk/mysqlfaq