Re: My rant about unix home directories



Pointless rant. In a typical set up the database server isn't
accessible to the outside world, so the risk of exposure through a
misconfigured web server isn't that unreasonable to take. The database
login/password is only useful to someone who can access the
database--i.e. another account on the same server. Putting your config
file your home directory does not prevent him from reading it.

Ideally any sensitive info should be stored in httpd.conf, readable
only by root.

.



Relevant Pages

  • Re: ER question
    ... backup to set up another test environment. ... How do I get CDR to stop ... remove onconfig [-c server] OnconfigText ... step depends on the database server you are using. ...
    (comp.databases.informix)
  • Re: SQL Timeout problem
    ... > your server. ... > If you do not see any blocking spids you should look at system resources. ... >> affected webserver, restart the database server, restart the database ... >> database server or service my gut feeling is that the problem must lie ...
    (microsoft.public.sqlserver.server)
  • Question about remote objects
    ... client manager to service logins from client workstations ... the server. ... a row read in from the database, and with multiple users running multiple ... instead of the database server exposing each object ...
    (comp.lang.python)
  • Re: Trouble connecting to IDS 11.5 development server using SQuirrel SQL with IDS JDBC driver.
    ... Connection closed by foreign host. ... -908 Attempt to connect to database server failed. ... see the IBM Informix Guide to SQL: ...
    (comp.databases.informix)
  • RE: Firewall DMZ
    ... Subject: Firewall DMZ ... database server on its own network section. ... web server, and another to the internal net. ... DMZ and the Database server in the protected LAN, ...
    (Security-Basics)