Create separate system user accounts for each database user and use suEXEC. Then place the passwords into the user's home directory, readable only by that user
That way, even if one account gets compromised somehow, the attacker can only read the database password of this individual user.
In reply to Re: Securing the database password for web applications
by tirwhan
in thread Securing the database password for web applications
by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |