Chapter 12 . Security 325 Note If the
Chapter 12 . Security 325 Note If the FILE privilege is given to a user, that user will be able to read the contents of all other databases on the server. The privileges are simple insofar as they mean what they are named. To issue a SELECT statement, you need the SELECTprivilege, to insert data you need the INSERT privilege, and so on. Security of passwords Working with an Internet service provider, I can t count the number of times I ve seen people choose bad passwords. I ve seen all the mistakes in the book, from choosing the username as the password to using the worst old favorite possible (the word password). I believe these types of mistakes are, in the words of James R. Leu, completely unacceptable. Regular users may have an excuse for choosing poor passwords, but System and Database Administrators don t. As the person who is in charge of a server or servers, it is your job to use passwords that cannot be easily guessed or cracked. Password guidelines I ve put together some guidelines that should help you choose effective passwords, come up with stronger ones, and keeping the ones you have secure. . Passwords should be six characters at an absolute minimum. . Passwords should include a mix of alphanumeric characters such as letters and numbers and non-alphanumeric characters, such as @#$^&* . . When you create a password, never use words that you can find in a dictionary (or those same words spelled backwards). . Passwords should include the use of both sides of the keyboard or both hands while typing. In other words, don t use passwords that require you to use only your left hand or the left side of the keyboard only. . Passwords should be different across servers. Don t use the same password for all of your servers, routers, and other gear. Thus, if one machine is compromised, the attacker cannot automatically gain access to your other servers. . Don t write your passwords down. If you feel you can t remember a password and must write something down, write down a word or phrase that will remind you of the password.
We recommend you use shared web hosting services, because many users agree that it is cheap, reliable and customer-satisfying webhost.