Welcome to Geeklog, Anonymous Saturday, December 21 2024 @ 01:28 pm EST
Geeklog Forums
non plain text passwords on server
Status: offline
spidermann
Forum User
Junior
Registered: 11/29/04
Posts: 26
Location:Handbasket, Satan
Spammers attacked and got into two sites of mine. The host is stating that it is because of the plain text passwords in the config file(s).
I know of no other way to put the SQL password into GL. Maybe someone can shed some light on how to not have the password plain text and GL still work?
would be much appreciated.
I know of no other way to put the SQL password into GL. Maybe someone can shed some light on how to not have the password plain text and GL still work?
would be much appreciated.
12
11
Quote
Status: offline
Dirk
Site Admin
Admin
Registered: 01/12/02
Posts: 13073
Location:Stuttgart, Germany
Well, the password has to be stored somewhere. Where else would you suggest to store it (and how)?
The config.php file should not be accessible other than through direct or ftp access to your webserver. And if someone gains that sort of access, you have much bigger problems to deal with than that ...
bye, Dirk
The config.php file should not be accessible other than through direct or ftp access to your webserver. And if someone gains that sort of access, you have much bigger problems to deal with than that ...
bye, Dirk
11
12
Quote
Status: offline
1000ideen
Forum User
Full Member
Registered: 08/04/03
Posts: 1298
spidermann you should request a more detailed infomation of your host WHY he thinks this is dangerous. I think this is nonsense. Almost all the blogs or portals store the passwords like that. There must be a misunderstanding.
Anyway where is your config on the server? Below public_html?
Anyway where is your config on the server? Below public_html?
12
15
Quote
Status: offline
spidermann
Forum User
Junior
Registered: 11/29/04
Posts: 26
Location:Handbasket, Satan
The config is before public_html where it should be. no config file is ever put in public_html but they seem to think that it was the reason the spammers got in.
They refuse to think that it was their servers, or a fault of their servers, for the attack. Even after I pointed out to them that GL had not been running on one of the sites in over nine months, and nothing was configured for GL on that site as I had deleted it all.
Yeah, they are sucking at the moment.
Dirk - I wasn't suggesting a different spot or anything. I know that the password is safe as it is. I was just asking to see if there was something I didn't know so that I could make sure it was the host being idiotic and not me.
They refuse to think that it was their servers, or a fault of their servers, for the attack. Even after I pointed out to them that GL had not been running on one of the sites in over nine months, and nothing was configured for GL on that site as I had deleted it all.
Yeah, they are sucking at the moment.
Dirk - I wasn't suggesting a different spot or anything. I know that the password is safe as it is. I was just asking to see if there was something I didn't know so that I could make sure it was the host being idiotic and not me.
13
9
Quote
All times are EST. The time is now 01:28 pm.
- Normal Topic
- Sticky Topic
- Locked Topic
- New Post
- Sticky Topic W/ New Post
- Locked Topic W/ New Post
- View Anonymous Posts
- Able to post
- Filtered HTML Allowed
- Censored Content