note 29421 deleted from function.mssql-connect by cmb
| From: | cmb@php.net | Date: | Sun, 11 Aug 2019 12:40:28 +0000 |
| Subject: | note 29421 deleted from function.mssql-connect by cmb | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-211861@lists.php.net to get a copy of this message | ||
Note Submitter: Gordon McCague
----
I am running PHP 4.2.1, Windows 2000, with a MSSQL Server 7.0 isolated from our web DMZ (separate
DMZ for our SQL Server).
mssql_connect in version 4.2.1 seems to insist on using named pipes to connect to the SQL Server.
This is not secure as it requires netbios browsing (tcp/udp ports 137, 139, and 445 (with
windows2000)). This is an unacceptable security risk.
To resolve this issue use your MSSQL 7.0 CD to perform a install on your web server. Select a
custom install. You will be prompted to select your components. Uncheck the "Server
Components" box to avoid installing the full server offering. Leave "Client
Connectivity" checked.
You can leave "Management Tools" selected as well if you wish to test your connection or
run queries against the database engine. Installing them may pose a security risk so some might not
choose to do so.
Don't forget to install the latest service pack and MDAC components once the initial
installtion is complete. The MDAC components can be obtained from http://www.microsoft.com/data/
SQL Service Packs can be obtained from http://www.microsoft.com/sql
Once you have installed the updates and patchs then you need to run the "Client Network
Utility" to enable TCPIP as the network protocol for connectivity to your SQL Server.
You will need to enable TCPIP and also create an alias to your SQL Server for TCPIP. This process
should be self-evident once you run the utility. You may want to consult the SQL online manuals for
assistance if uncomfortable with the configuration.
This should now allow you to access your SQL Server via ports 1433 and 1434 (or whatever you have
enable as the port of communication). It is a best practice to consider changing the ports of
communication to the SQL Server and I believe this can be done with the Network Client Utility (to
something other than 1433 and 1434).
You can always build a little test file to check your connectivity once your system is up and
running.
Good luck!
P.S. I have not looked to see if PHP 4.3.0 resolves this issue but I don't plan to test too
much. I like to know how the web servers are connected to the SQL server.