[KLUG Members] database programming question

Bruce Smith bruce at armintl.com
Tue Jun 22 16:02:55 EDT 2004


> > Practically speaking, once a MySQL database is created with a
> > couple of logons, I can put up PHPMyAdmin and run major
> > websites without ever again using a shell.  That's ease of use.
> 
> I worry a bit about PHPMyAdmin...

I worry about any package that has that kind of power over the database!

This is why I went though the roof awhile back when a web designer here
installed a similar package on our web server, without any access
controls to the internet.  Yikes!  :-)

BTW, the PG package similar to PHPMyAdmin I forgot the name before is: 
PHPPgAdmin  http://phppgadmin.sourceforge.net/  (imagine that! :)

> That was fixed in February, but since then, there's also been
> a security fix about "cookie hijacking" or something.  Best
> if you can make sure your PHPMyAdmin server runs only on an
> internal network, I think...

Absolutely!!! 
Almost goes without saying (which is why I didn't say it! ;)

> For the record, the "P" in "LAMP" stands for either PHP or Perl,
> your choice.  :)

There we go, let's get a PHP vs. [mod] Perl debate going!
This DB "debate" is getting old!  ;-)

 - BS




More information about the Members mailing list