Re: secure connectin to mysql
| From: | Richard Lynch | Date: | Tue, 12 Dec 2000 04:28:00 +0000 |
| Subject: | Re: secure connectin to mysql | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-29807@lists.php.net to get a copy of this message | ||
> How secure is the php>mysql database connection?
> Does it use SSL or is it transmitted in the clear?
It does not use SSL, almost for sure.
I'm not 100% sure about MySQL, but if you use PostgreSQL, and it's on
localhost, you can restrict connections to use Un*x sockets rather than
TCP/IP. This means that the data is all handled by internal RAM structures
on your box -- If a hacker can read that, you have bigger problems than your
databasea security.
If MySQL can do the same, you're all set.
If not, you could probably add a second network card, and route all
PHP->MySQL traffic through that somehow. For sure you can do this if you
are using two machines.
Note that the username/password to actually connect to the database is on
your web-server, so there is only so much you can do to keep your database
content secure...