Perl Monk, Perl Meditation | |
PerlMonks |
Re^3: DBI & CGI Securityby samtregar (Abbot) |
on Jun 03, 2004 at 16:54 UTC ( [id://360274]=note: print w/replies, xml ) | Need Help?? |
What kind of attack are you trying to prevent? Are you trying to make it so that an attacker could get into the web server but not be able to get into the database? That's an unusual requirement...
I'm not sure what the best way to do it would be. Maybe encrypt the DB password and store it on disk. Then require the admin to enter the decryption password whenever the server is started. The server would load the decrypted password into memory and use it to connect to the DB. It's still vulnerable to a root compromise since the plaintext password will exist in memory, but it would keep the password unreadable on disk. You'd still be vulnerable to key-loggers and the like, of course. Ultimately it's hard to create a system that can do a given job but won't let an attacker do the same job if they break in. -sam
In Section
Seekers of Perl Wisdom
|
|