Re: WAYS OF AUTHENICATION - open discussion

From: Date: Sat, 04 Nov 2000 10:14:42 +0000
Subject: Re: WAYS OF AUTHENICATION - open discussion
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-23692@lists.php.net to get a copy of this message
> >Don't make mysql users. That is wrong. > > I don`t, but I do know people who make. What is so bad about? Of course, > when there will be very many users..but why this is so bad solution? The model just isn't right. Mostly those users are used as a means of authenticating users for use against the SQL server. To contrast, you will only have one user accessing your database (the user that the web server is running under -- usually nobody). > > >The first and second ideas are the correct ones whether you do hand > >written sessions or use PHP4. The part that I think you are missing > >is that the "session" is a unique key so to speak that lets the user > >be active. > > I understand that. I have used it myself:-) But probably I just didn´t > make myself clear enough. > > >Another part is that this table that holds the sessions > >usually gets cleaned out by something running in cron -- basically > >nuking any "expired" sessions. > > In my case, this is cleaned usually by a logout button or in case someone > exits in some otehr way, the session will be deleted when someone > activates the login page again. > > >This prevents what you have > >stated, that if soneone knew the session, they can get in. > > I`m not talkin about people to get to know the sessions, but rather > usernames and passwords. For example: lets say that I have a file called > connect.inc.php3 and I have included to every page that I have. The file > itself contains the following information: > $db = mysql_connect("somehost","someuser","somepass"); > Now when somone knows the filename (inthis case connect.inc.php3) and he > knows the variable name (in this case $db), he can include theinc file in > is own page and echo the $db and so getting to know the mysql user > information. This shouldn't be a problem is you are the administrator of the machine. If you are not, and you have a service provider that doesn't have good security in place (this exact problem exists on HE.NET's servers), you really do need to flame them until they find a solution. -jeremy brand _______________________________________________________________________ GnuPG Fingerprint: 9F5E 95E0 1CC2 E054 84EA 6099 8ACD 9DBA D2C0 5EA9 _ http://www.JeremyBrand.com/Jeremy/Brand/Jeremy_Brand.html for more __

« previous php.general (#23692) next »