note 29421 added to function.mssql-connect

From: Date: Thu, 13 Feb 2003 05:27:23 +0000
Subject: note 29421 added to function.mssql-connect
Groups: php.notes 
Request: Send a blank email to php-notes+get-43863@lists.php.net to get a copy of this message
I am running PHP 4.2.1, Windows 2000, with a MSSQL Server 7.0 isolated from our web DMZ (separate DMZ for our SQL Server). mssql_connect in version 4.2.1 seems to insist on using named pipes to connect to the SQL Server. This is not secure as it requires netbios browsing (tcp/udp ports 137, 139, and 445 (with windows2000)). This is an unacceptable security risk. To resolve this issue use your MSSQL 7.0 CD to perform a install on your web server. Select a custom install. You will be prompted to select your components. Uncheck the "Server Components" box to avoid installing the full server offering. Leave "Client Connectivity" checked. You can leave "Management Tools" selected as well if you wish to test your connection or run queries against the database engine. Installing them may pose a security risk so some might not choose to do so. Don't forget to install the latest service pack and MDAC components once the initial installtion is complete. The MDAC components can be obtained from http://www.microsoft.com/data/ SQL Service Packs can be obtained from http://www.microsoft.com/sql Once you have installed the updates and patchs then you need to run the "Client Network Utility" to enable TCPIP as the network protocol for connectivity to your SQL Server. You will need to enable TCPIP and also create an alias to your SQL Server for TCPIP. This process should be self-evident once you run the utility. You may want to consult the SQL online manuals for assistance if uncomfortable with the configuration. This should now allow you to access your SQL Server via ports 1433 and 1434 (or whatever you have enable as the port of communication). It is a best practice to consider changing the ports of communication to the SQL Server and I believe this can be done with the Network Client Utility (to something other than 1433 and 1434). You can always build a little test file to check your connectivity once your system is up and running. Good luck! P.S. I have not looked to see if PHP 4.3.0 resolves this issue but I don't plan to test too much. I like to know how the web servers are connected to the SQL server. -- http://www.php.net/manual/en/function.mssql-connect.php http://master.php.net/manage/user-notes.php?action=edit+29421 http://master.php.net/manage/user-notes.php?action=delete+29421 http://master.php.net/manage/user-notes.php?action=reject+29421

« previous php.notes (#43863) next »