Forums » General Discussion

Thread: Let's get this started.

This question is not answered. Helpful answers available: 2. Answered answers available: 1.


Permlink Replies: 1 - Pages: 1 - Last Post: Mar 9, 2010 11:22 PM by: DocJones
Dwight


Posts: 68
Registered: 8/22/07
Let's get this started.
Posted: Mar 9, 2010 12:29 PM
 
  Click to reply to this thread Reply

Well, I haven't seen much traffic in this forum, so I'll try and get things started. Let's talk security issues.

What's your policy on opening a MySQL database inside a firewall?

What's your policy for running a MySQL database on a website?


Let's hear from you guys.


DocJones


Posts: 50
Registered: 2/22/10
Re: Let's get this started.
Posted: Mar 9, 2010 11:22 PM   in response to: Dwight
 
  Click to reply to this thread Reply

Heyas,

I am not really an MySQL administrative expert, so i always leave the root user untouched (i only set the password).

I create a dedicated user for a certain application and set it up to work from a certain host (i.e. Webserver). The access restriction will be set to a minimum as the application requires (only SELECT's etc).

For development i create a 2nd administrative user restircted to certain source host(s) with full database access.

I would be happy to hear from others (be it their solution or their crticism) :)

regards
/Marc


Level 197 Nanomage NT from Rimor speaking... err, wait: Wrong Forum!
Legend
Guru: 2001 + pts
Expert: 751 - 2000 pts
Enthusiast: 31 - 750 pts
Novice: 0 - 30 pts
Moderators
Helpful answer (5 pts)
Answered (10 pts)

Point your RSS reader here for a feed of the latest messages in all forums