Raised This Month: $51 Target: $400
 12% 

Secure or hide database.cfg


Post New Thread Reply   
 
Thread Tools Display Modes
DarkDeviL
SourceMod Moderator
Join Date: Apr 2012
Old 01-31-2018 , 11:18   Re: Secure or hide database.cfg
Reply With Quote #11

Quote:
Originally Posted by fragnichtnach View Post
Okay, thanks for explaining that there is absolutely no security. I understand this.
Obviously, you don't understand:

As you were previously told, all what you say is a "FALSE" sense of security. Also the thing referred to as "security by obscurity".

If your server should be able to use databases.cfg, it will also need to be able to decipher it. If your server can automatically decipher the data, EVERYONE with access to your server can then decipher your data by grabbing the features of your requested plugin.

Are you also locking your door, but leaving your keys on your doorstep? Your requested "plugin" here would be no different than doing that!
__________________
Mostly known as "DarkDeviL".

Dropbox FastDL: Public folder will no longer work after March 15, 2017!
For more info, see the [SRCDS Thread], or the [HLDS Thread].

Last edited by DarkDeviL; 01-31-2018 at 11:27.
DarkDeviL is offline
ddhoward
Veteran Member
Join Date: May 2012
Location: California
Old 01-31-2018 , 14:55   Re: Secure or hide database.cfg
Reply With Quote #12

Quote:
Originally Posted by fragnichtnach View Post
I could try to read the code out of sourcemod. Anybody know what plugin is reading the database.cfg? Not sure if that will tell me the answer... but maybe.
There is no such plugin.

https://github.com/alliedmodders/sou...c/Database.cpp
__________________
ddhoward is offline
balonfx
AlliedModders Donor
Join Date: Dec 2013
Location: New Haven, CT
Old 01-31-2018 , 19:19   Re: Secure or hide database.cfg
Reply With Quote #13

For secondary techs, jail your users in certain directories or omit others from your FTP software.

For example, for our community we jail our staff in directories they cannot exit, and either access resources out of their scope, or hide certain files/paths/etc.


You will need software or heavy configuration to make this possible, however.
__________________
balonfx is offline
ddhoward
Veteran Member
Join Date: May 2012
Location: California
Old 01-31-2018 , 20:07   Re: Secure or hide database.cfg
Reply With Quote #14

Quote:
Originally Posted by balonfx View Post
For secondary techs, jail your users in certain directories or omit others from your FTP software.

For example, for our community we jail our staff in directories they cannot exit, and either access resources out of their scope, or hide certain files/paths/etc.


You will need software or heavy configuration to make this possible, however.
The OP is the user to be jailed. He's concerned about server hosting companies (or malicious actors who have penetrated the hosts' security measures) peeking through his files and retrieving any database passwords that are present in config files. You can "jail" files behind all the doors and locks that you want, but that's all useless if the landlord automagically has a master key to everything.


The overarching issue here is one that I have yet to find a decent solution to. I remember that back when I ran the website for my high school, my configuration files for MediaWiki and Moodle contained database passwords in cleartext. This is unavoidable unless, as asherkin pointed out, you're willing to manually enter passwords or decryption keys on every single boot.
__________________

Last edited by ddhoward; 01-31-2018 at 20:11.
ddhoward is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 11:17.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode