note 1193 deleted from features.http-auth by betz

From: Date: Thu, 01 Apr 2004 12:00:44 +0000
Subject: note 1193 deleted from features.http-auth by betz
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-67464@lists.php.net to get a copy of this message
Note Submitter: fredrick-realm@home.com ---- A few notes on authentication in which it's possible I overlooked some things. Considering a prior post about using the same salt for all users so you can match passwords; I think it would be better to not do so, as you can figure out the salt from the password and match. (Example, salt in DES if I'm not mistaken is the first 2 characters) Something I've been trying to figure out is secure apache module PHP on a multi-user server. Delima (with postgres)- any user can write a PHP page to read another users databases. Set your database to connect using username and password, and any user can read your username and password from wherever you place them. (use PHP function to read it and as it has to be readable by your web process for you to read it, they can) The closest I've come to a solution for this is to run php as a CGI module with suexec or cgiwrap. Hopefuly someone else has a better solution; otherwise, something to think about before you think of your databases as being secure with php interfacing to them.

« previous php.notes (#67464) next »