try another color scheme:


Go Back   TECH6.0 > Web Design/Development and SEO > Website Development


Insecure?

This is a discussion on Insecure? within the Website Development section, part of the Web Design/Development and SEO category; I'm considering creating an account on my VPS which has read-only access to a MySQL database which contains no sensitive ...

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 20-10-2009, 05:23 PM
eL3's Avatar
eL3 eL3 is offline

Learner
 
Join Date: Oct 2009
Posts: 29
eL3 is on a distinguished road
Default Insecure?

I'm considering creating an account on my VPS which has read-only access to a MySQL database which contains no sensitive data.
I will then release code which allows people to log into my site from their server, and read data which they need. All data within the database is freely available to anyone who wishes to see, but what I'm worried about is whether or not this could allow remote SQL commands to be given.

Are you guys understanding what I'm saying? Or should I say it more clearer..
The password is 100% guessable and 100% different from any password used by myself or the server, the user account will have read-only permissions to a database which has no sensitive data what-so ever. No passwords, not even a username. It goes as far as having a client number, and a few values which I feel other sites within my niche could benefit from. Furthermore, users of my system would benefit from the certralization of data which has been lost over countless failed websites.

But I can't really see any reason my system would produce a security risk, am I over-seeing something?
Reply With Quote
  #2  
Old 21-10-2009, 05:33 PM
Shocker's Avatar

Techie
 
Join Date: Sep 2009
Posts: 48
Shocker is on a distinguished road
Default

I'm considering creating an account on my VPS which has read-only access to a MySQL database which contains no sensitive data.
I will then release code which allows people to log into my site from their server, and read data which they need.
As Said by eL3 View Post
What does the bold part means? Log into your site from their server?

All data within the database is freely available to anyone who wishes to see, but what I'm worried about is whether or not this could allow remote SQL commands to be given.
As Said by eL3 View Post
You mean SQL injection? It depends on your code really. I think this is what we call Input Filtering where you clean the data what the user has entered before it touches the database.

But I can't really see any reason my system would produce a security risk, am I over-seeing something?
As Said by eL3 View Post
I can't see a flaw either. Things would itself become more clear once your system goes live.
Reply With Quote
  #3  
Old 21-10-2009, 06:55 PM
eL3's Avatar
eL3 eL3 is offline

Learner
 
Join Date: Oct 2009
Posts: 29
eL3 is on a distinguished road
Default

It's not a matter of code, none of this is handled by PHP code on my side.
The part that you bolded means; the admin uploads a PHP file to their server that, when accessed, connects to my servers' MySQL database. The account they use to connect has strictly read-only privileges.

The system won't be live for a while now. I need to finish coding my CMS and plugin-modules before I can even begin setting up the various expansions I want.
Reply With Quote
  #4  
Old 23-10-2009, 10:07 AM
Prateek_m's Avatar

Tech Addict
 
Name: Prateek
Join Date: Sep 2009
Location: India
Posts: 103
Prateek_m is on a distinguished road
Default

So why do have to worry when the account they'll use to connect has strictly read-only privileges? If not code, then for what possible reasons can you see your application to be insecure?
__________________
Reply With Quote
  #5  
Old 21-03-2011, 03:59 PM
No Avatar

Techie
 
Join Date: Mar 2011
Posts: 26
sidharthbanyal is on a distinguished road
Default

It should not affect if account have read only privilege.
Reply With Quote
  #6  
Old 08-04-2011, 11:13 AM
No Avatar

Learner
 
Join Date: Apr 2011
Posts: 1
tootatomy is on a distinguished road
Default

Trust them and don't second guess yourself.
__________________
china dropship china wholesale
Reply With Quote
  #7  
Old 08-04-2011, 12:44 PM
No Avatar

Learner
 
Join Date: Apr 2011
Posts: 1
moshun111 is on a distinguished road
Default

just listen to romantic music it should make your view on love more strong. music is what helps me in any situation.
__________________
china wholesale wholesale
Reply With Quote
  #8  
Old 21-11-2011, 04:01 PM
No Avatar

Learner
 
Join Date: Nov 2011
Posts: 10
suba is on a distinguished road
Default

Thanks to given good information.
Reply With Quote
Reply

Bookmarks


Thread Tools
Display Modes




All times are GMT +5.5. The time now is 02:42 PM.

Contact Us - Tech6.com - Link to Us - Advertise - Submit Site - Privacy Statement - TOS - Top