Re: SQL Access Problem

From: Marc Ende (me@nowhere-operations.net)
Date: 10/25/01


Message-ID: <200110251013580927.0E5520E3@smtp.puretec.de>
Date: Thu, 25 Oct 2001 10:13:58 +0200
From: "Marc Ende" <me@nowhere-operations.net>
To: "jaywhy" <jaywhy2@home.com>, focus-linux@securityfocus.com
Subject: Re: SQL Access Problem

Hi jaywhy,

it's a little bit of security by obscurity.
But this is one way, If other users can't get into your directory (thats why "chrooted"), then
they have to guess a) the name of your server root, b) the location of your account-data and
c) you don't need to use suExec (I don't like it, but this is only my personal opinion).

Marc

*********** REPLY SEPARATOR ***********

On 24.10.2001 at 20:05 jaywhy wrote:

>Chrooting ftpd will not help stop Apache from executing CGI that print outs
>the configuration file. Shell access doesn't matter either, since someone
>could just upload the script. As for changing the configuration file name
>to something obscure, sounds like security by obscurity.



Relevant Pages

  • RE: Concepts: Security and Obscurity
    ... resources are limited and thus there is a cost to life. ... It is not obscurity in the manner being ... more you spend on security the less of an advantage is gained. ... It also ignores the requirements of a control function. ...
    (Security-Basics)
  • RE: Re: Concepts: Security and Obscurity
    ... so long as you understand that the server location and port number ... security in the slightest." ... Beale's assertion that "Obscurity Potentially Slows Down the Attacker". ... BDO Kendalls is a national association of separate partnerships and entities. ...
    (Security-Basics)
  • Re: NAT external/Public IP
    ... I remember working for an ISP a long while back that was threatened to be disconnected from the Internet if they did not stop routing the 10.x range in their BGP tables. ... Any views expressed in this message are those of the individual sender and not necessarily endorsed by BDO Kendalls. ... Why not Security by Design plus Security by Obscurity? ...
    (Security-Basics)
  • RE: Concepts: Security and Obscurity
    ... Subject: Concepts: Security and Obscurity ... I have at no point claimed absolute security measures or cost ... It also ignores the requirements of a control function. ...
    (Security-Basics)
  • RE: Re: Concepts: Security and Obscurity
    ... Subject: Concepts: Security and Obscurity ... BDO Kendalls is a national association of separate partnerships and entities. ... Maybe we can all agree that "port obscurity" is a special case of STO. ...
    (Security-Basics)