Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old July 18th, 2003, 06:59 PM
killerchick killerchick is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2003
Location: Georgia
Posts: 2 killerchick User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
database and php security

I am a web hosting reseller and I have a possible client asking about security for his data stored in a MySql database and accessed by php. This data will be from a small county government and will only contain public documents.

Each domain on my host gets its own database but no control over the database installation so I really don't know - besides the version - what I'm looking at.

I know to use phpinfo file to get that info. I know that the databases are all accessed via localhost, php 4.2.3 is operating in safe mode and the mysql version is 3.23.39.

What else can I tell about the possible security problems with this system by looking at the info file?

Secondly, I use a wide variety of php open source code on this server and I have no earthly idea how safe this stuff is. I am no programmer but I'm learning fast how to work with already made files.

Please, some words of advice!

Reply With Quote
  #2  
Old July 19th, 2003, 10:19 AM
victorpendleton victorpendleton is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Jan 2003
Location: No es importante
Posts: 2,065 victorpendleton User rank is Private First Class (20 - 50 Reputation Level)victorpendleton User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 6 h 50 m 52 sec
Reputation Power: 8
You can restrict access to the MySQL server to either localhosts or from the webservers. If it is possible I would recommend using ssl to run your scripts.

Reply With Quote
  #3  
Old July 20th, 2003, 04:27 PM
killerchick killerchick is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2003
Location: Georgia
Posts: 2 killerchick User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Okay, localhost is what is happening. I can to go to ssl as well when accessing and using the admin functions. Anybody else got words of wisdom? Thank you, Victor

Reply With Quote
  #4  
Old July 27th, 2003, 01:03 AM
alexgreg's Avatar
alexgreg alexgreg is offline
Full Access
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Jun 2000
Location: London, UK
Posts: 2,019 alexgreg User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 3 sec
Reputation Power: 11
Quote:
Each domain on my host gets its own database but no control over the database installation so I really don't know - besides the version - what I'm looking at.

What are you looking for?
Quote:
I know to use phpinfo file to get that info. I know that the databases are all accessed via localhost, php 4.2.3 is operating in safe mode and the mysql version is 3.23.39.

Both PHP and MySQL can be upgraded to more recent (and probably more secure) versions, as you are not running the latest stable version of either.

Quote:
What else can I tell about the possible security problems with this system by looking at the info file?

Probably not a great deal. The security of each aspect of your system would need to be analysed by a professional in order to highlight areas of weakness.
Quote:
Secondly, I use a wide variety of php open source code on this server and I have no earthly idea how safe this stuff is. I am no programmer but I'm learning fast how to work with already made files.

Since PHP runs with the privileges of the web server, this limits the amount of damage it can do to the amount of damage that the "nobody" user can do - however this depends very much on what this user can do with regards to reading and writing files. For example, users can overwrite each other's files via PHP if their permissions are 777.
__________________
Alex
(http://www.alex-greg.com)

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > database and php security


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway
Stay green...Green IT