| |||||||
This is a discussion on Insecure? within the Website Development section, part of the Web Design/Development and SEO category; I'm considering creating an account on my VPS which has read-only access to a MySQL database which contains no sensitive ...
![]() |
|
| | LinkBack | Thread Tools | Display Modes |
|
#1
| ||||
| ||||
|
I'm considering creating an account on my VPS which has read-only access to a MySQL database which contains no sensitive data. I will then release code which allows people to log into my site from their server, and read data which they need. All data within the database is freely available to anyone who wishes to see, but what I'm worried about is whether or not this could allow remote SQL commands to be given. Are you guys understanding what I'm saying? Or should I say it more clearer.. The password is 100% guessable and 100% different from any password used by myself or the server, the user account will have read-only permissions to a database which has no sensitive data what-so ever. No passwords, not even a username. It goes as far as having a client number, and a few values which I feel other sites within my niche could benefit from. Furthermore, users of my system would benefit from the certralization of data which has been lost over countless failed websites. But I can't really see any reason my system would produce a security risk, am I over-seeing something? |
|
#2
| ||||
| ||||
![]() I can't see a flaw either. Things would itself become more clear once your system goes live. |
|
#3
| ||||
| ||||
|
It's not a matter of code, none of this is handled by PHP code on my side. The part that you bolded means; the admin uploads a PHP file to their server that, when accessed, connects to my servers' MySQL database. The account they use to connect has strictly read-only privileges. The system won't be live for a while now. I need to finish coding my CMS and plugin-modules before I can even begin setting up the various expansions I want. |
|
#4
| ||||
| ||||
|
So why do have to worry when the account they'll use to connect has strictly read-only privileges? If not code, then for what possible reasons can you see your application to be insecure?
__________________ |
|
#5
| ||||
| ||||
|
It should not affect if account have read only privilege.
|
|
#6
| ||||
| ||||
|
Trust them and don't second guess yourself.
|
|
#7
| ||||
| ||||
|
just listen to romantic music it should make your view on love more strong. music is what helps me in any situation.
|
|
#8
| ||||
| ||||
|
Thanks to given good information.
__________________ software testing institutes chennai |
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
| |