Re: WAYS OF AUTHENICATION - open discussion
| From: | jeremy brand | Date: | Sat, 04 Nov 2000 10:14:42 +0000 |
| Subject: | Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23692@lists.php.net to get a copy of this message | ||
> >Don't make mysql users. That is wrong.
>
> I don`t, but I do know people who make. What is so bad about? Of course,
> when there will be very many users..but why this is so bad solution?
The model just isn't right. Mostly those users are used as a means of
authenticating users for use against the SQL server. To contrast, you
will only have one user accessing your database (the user that the web
server is running under -- usually nobody).
>
> >The first and second ideas are the correct ones whether you do hand
> >written sessions or use PHP4. The part that I think you are missing
> >is that the "session" is a unique key so to speak that lets the user
> >be active.
>
> I understand that. I have used it myself:-) But probably I just didn´t
> make myself clear enough.
>
> >Another part is that this table that holds the sessions
> >usually gets cleaned out by something running in cron -- basically
> >nuking any "expired" sessions.
>
> In my case, this is cleaned usually by a logout button or in case someone
> exits in some otehr way, the session will be deleted when someone
> activates the login page again.
>
> >This prevents what you have
> >stated, that if soneone knew the session, they can get in.
>
> I`m not talkin about people to get to know the sessions, but rather
> usernames and passwords. For example: lets say that I have a file called
> connect.inc.php3 and I have included to every page that I have. The file
> itself contains the following information:
> $db = mysql_connect("somehost","someuser","somepass");
> Now when somone knows the filename (inthis case connect.inc.php3) and he
> knows the variable name (in this case $db), he can include theinc file in
> is own page and echo the $db and so getting to know the mysql
user
> information.
This shouldn't be a problem is you are the administrator of the
machine. If you are not, and you have a service provider that doesn't
have good security in place (this exact problem exists on HE.NET's
servers), you really do need to flame them until they find a solution.
-jeremy brand
_______________________________________________________________________
GnuPG Fingerprint: 9F5E 95E0 1CC2 E054 84EA 6099 8ACD 9DBA D2C0 5EA9
_ http://www.JeremyBrand.com/Jeremy/Brand/Jeremy_Brand.html
for more __