note 1193 deleted from features.http-auth by betz
| From: | betz@php.net | Date: | Thu, 01 Apr 2004 12:00:44 +0000 |
| Subject: | note 1193 deleted from features.http-auth by betz | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-67464@lists.php.net to get a copy of this message | ||
Note Submitter: fredrick-realm@home.com
----
A few notes on authentication in which it's possible I overlooked some things. Considering a
prior post about using the same salt for all users so you can match passwords; I think it would be
better to not do so, as you can figure out the salt from the password and match. (Example, salt in
DES if I'm not mistaken is the first 2 characters)
Something I've been trying to figure out is secure apache module PHP on a multi-user server.
Delima (with postgres)- any user can write a PHP page to read another users databases. Set your
database to connect using username and password, and any user can read your username and password
from wherever you place them. (use PHP function to read it and as it has to be readable by your web
process for you to read it, they can)
The closest I've come to a solution for this is to run php as a CGI module with suexec or
cgiwrap.
Hopefuly someone else has a better solution; otherwise, something to think about before you think
of your databases as being secure with php interfacing to them.