PHP is not only for web server "scripting", if you write shell/Perl scripts to maintain database, read this.
Posted in 2000
Not a problem report but an advocacy post: Andrej Falout suggests PHP (built as a standalone/CGI binary with the Informix ifx_* functions) as an alternative to dbaccess shell scripts or Perl DBD::Informix, so the same code can run from the command line and from a web server, with a sample sysmaster query script. Replies note tcl/tk can also reach Informix and be embedded in HTML, and Jonathan Stowe objects that putting the interpreter in cgi-bin is a long-standing security risk (CERT advisory) and questions the thread's relevance to Informix. The exchange ends in disagreement with no resolution.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Connectivity: ODBC / JDBC / .NET, Connectivity: ESQL/C, 4GL & Embedded SQL, Server Administration, Security, Permissions & Auditing
Hi all,
I would like to spread the word about PHP, in context of database
interaction scripting.
Untill recently, there where two choices to do this:
a) shell scripts using dbaccess to interact with database;
b) Perl and DBD::Informix interface
Now, how do you like idea to consolidate scripting across web servers
and shell? Many folks here already know where future of server side
"scripting" for web servers is, and it's called PHP.
What many missed, is this:
1) compile PHP as CGI executable with Informix (or ODBC, or any other
database) support.
2) save this script in file, make it executable and try it on command
line:
------------------------- cut here ------------------------
#!/path/to/webserver/cgi-bin/php -q
<script language="php">
echo "start";
$tmpconnid = ifx_connect("sysmaster@".
$dbserver_name."_on","informix","mypassword") or
die("Couldn't connect to the database server!");
echo "connected to $db_data";
$rid = ifx_query("select tabname from systables", $tmpconnid);
$row = ifx_fetch_row ($rid, "FIRST");
if ($row == FALSE) { die("not data!");} else { echo "data
selected"; }
ifx_free_result($rid);
ifx_close($tmpconnid);
echo "end";
</script>
----------------------------- cut here -------------------------------
3) now rename the script to have .php extension, put it in your web
server document tree and type it's URL in your web browser.
Why? Because it is extremely powerful. Because you will never ever need
to write things twice for shell and for web again.
More info: www.php.net
Yours, Andrej Falout, http://www.falout.com ICQ 7628616
#-----------------------------------------------------------------
globals "std_disclaimer.4gl"
"Venus is still under construction. Thank you for your patience
and we apologize for the inconvenience." - Match.com online dating site.
For completeness, there's also tcl/tk
Andy.
In article <MPG.138e15bdb9dceef39896d4@news.xtra.co.nz>, Andrej Falout
<afalout@xtra.co.nz> writes
>Hi all,
>
>I would like to spread the word about PHP, in context of database
>interaction scripting.
>Untill recently, there where two choices to do this:
>
>a) shell scripts using dbaccess to interact with database;
>
>b) Perl and DBD::Informix interface
>
>Now, how do you like idea to consolidate scripting across web servers
>and shell? Many folks here already know where future of server side
>"scripting" for web servers is, and it's called PHP.
>
>What many missed, is this:
>
>1) compile PHP as CGI executable with Informix (or ODBC, or any other
>database) support.
>
>2) save this script in file, make it executable and try it on command
>line:
>
>------------------------- cut here ------------------------
>
>#!/path/to/webserver/cgi-bin/php -q
>
><script language="php">
>echo "start";
> $tmpconnid = ifx_connect("sysmaster@".
>$dbserver_name."_on","informix","mypassword") or
> die("Couldn't connect to the database server!");
> echo "connected to $db_data";
> $rid = ifx_query("select tabname from systables", $tmpconnid);
> $row = ifx_fetch_row ($rid, "FIRST");
> if ($row == FALSE) { die("not data!");} else { echo "data
>selected"; }
> ifx_free_result($rid);
> ifx_close($tmpconnid);
>echo "end";
></script>
>
>----------------------------- cut here -------------------------------
>
>3) now rename the script to have .php extension, put it in your web
>server document tree and type it's URL in your web browser.
>
>Why? Because it is extremely powerful. Because you will never ever need
>to write things twice for shell and for web again.
>
>More info: www.php.net
>
>
>Yours, Andrej Falout, http://www.falout.com ICQ 7628616
>#-----------------------------------------------------------------
>globals "std_disclaimer.4gl"
>
>"Venus is still under construction. Thank you for your patience
>and we apologize for the inconvenience." - Match.com online dating site.
>
>
Andrew Lennard andy@kontron.demon.co.uk
On Thu, 18 May 2000 13:59:49 +1200, Andrej Falout Wrote:
> Hi all,
>
> I would like to spread the word about PHP, in context of database
> interaction scripting.
> Untill recently, there where two choices to do this:
>
> a) shell scripts using dbaccess to interact with database;
>
> b) Perl and DBD::Informix interface
>
> Now, how do you like idea to consolidate scripting across web servers
> and shell? Many folks here already know where future of server side
> "scripting" for web servers is, and it's called PHP.
>
> What many missed, is this:
>
> 1) compile PHP as CGI executable with Informix (or ODBC, or any other
> database) support.
>
> 2) save this script in file, make it executable and try it on command
> line:
>
> ------------------------- cut here ------------------------
>
> #!/path/to/webserver/cgi-bin/php -q
>
Oh yes. What host did you say you were running this on ?
<http://www.cert.org/advisories/CA-96.11.interpreters_in_cgi_bin_dir.html>
I would also see :
<http://www.w3.org/Security/Faq/www-security-faq.html>
While you are at it.
Quite what this has to do with Informix I'm not sure.
/J\\
In article <jGOU4.107$6T1.18753@news.dircon.co.uk>, gellyfish@gellyfish.com says... > On Thu, 18 May 2000 13:59:49 +1200, Andrej Falout Wrote: > > Hi all, > > ...snip... > > > > #!/path/to/webserver/cgi-bin/php -q > > > > Oh yes. What host did you say you were running this on ? Sinclair ZX spectrum (64K with microdrive) > <http://www.cert.org/advisories/CA-96.11.interpreters_in_cgi_bin_dir.html> "Many sites that maintain a Web server support CGI programs..." Extract: "Web server" > I would also see : > > <http://www.w3.org/Security/Faq/www-security-faq.html> "The World Wide Web Security FAQ" Extract: "Web Security" > While you are at it. While I am, I would suggest that you inform yourself that PHP can and in most cases does run as web server module, not CGI. I was talking about CGI compiled executable in the context of shell scripts. If you don't like /path/to/webserver/cgi-bin/php -q, then use /path/to/some/place/php -q. You don't need web server to compile or run PHP. > Quite what this has to do with Informix I'm not sure. Quite what this has to do with my post I'm not sure. -- Yours, Andrej Falout, http://www.falout.com ICQ 7628616 ++64.21.607517 #----------------------------------------------------------------- globals "std_disclaimer.4gl" Ask yourself just one question: ' Qu' m's se puede hacer y aprender ? - Propellerhead ReBirth RB-338 manual
In article <ShBvEBAwa4I5EwcF@kontron.demon.co.uk>, andy@kontron.demon.co.uk says... > For completeness, there's also tcl/tk > > Andy. > Can you run TCL/TK embeded in HTML ? Can you access Informix database via TCL/TK ? -- Yours, Andrej Falout, http://www.falout.com ICQ 7628616 ++64.21.607517 #----------------------------------------------------------------- globals "std_disclaimer.4gl" Ask yourself just one question: ' Qu' m's se puede hacer y aprender ? - Propellerhead ReBirth RB-338 manual
In article <MPG.138f445d46e4d7c09896d7@news.xtra.co.nz>, Andrej Falout <afalout@xtra.co.nz> writes >In article <ShBvEBAwa4I5EwcF@kontron.demon.co.uk>, >andy@kontron.demon.co.uk says... >> For completeness, there's also tcl/tk >> >> Andy. >> > >Can you run TCL/TK embeded in HTML ? I'm told you can, but it's not something I do. >Can you access Informix database via TCL/TK ? Yes. > > Andrew Lennard andy@kontron.demon.co.uk
On Fri, 19 May 2000 11:28:18 +1200, Andrej Falout Wrote: > In article <jGOU4.107$6T1.18753@news.dircon.co.uk>, > gellyfish@gellyfish.com says... >> On Thu, 18 May 2000 13:59:49 +1200, Andrej Falout Wrote: >> > Hi all, >> > > ...snip... >> > >> > #!/path/to/webserver/cgi-bin/php -q >> > >> >> Oh yes. What host did you say you were running this on ? > > Sinclair ZX spectrum (64K with microdrive) > >> <http://www.cert.org/advisories/CA-96.11.interpreters_in_cgi_bin_dir.html> > > "Many sites that maintain a Web server support CGI programs..." > Extract: "Web server" > You so conveniently snipped your original statement: >> Now, how do you like idea to consolidate scripting across web servers >> and shell? Many folks here already know where future of server side >> "scripting" for web servers is, and it's called PHP. I see two mentions of 'web server' there. > >> I would also see : >> >> <http://www.w3.org/Security/Faq/www-security-faq.html> > > > "The World Wide Web Security FAQ" > Extract: "Web Security" > >> While you are at it. > > > While I am, I would suggest that you inform yourself that PHP can and in > most cases does run as web server module, not CGI. I am perfectly well aware of what PHP is what its relationship to the server is and what its capabilities are. Thank you very much. > > I was talking about CGI compiled executable in the context of shell > scripts. If you don't like /path/to/webserver/cgi-bin/php -q, then use > /path/to/some/place/php -q. You don't need web server to compile or run > PHP. > Its not a matter of me not liking it - you advocated placing the language interpreter in the 'cgi-bin' directory of the server something which is explicitly warned against in the CERT advisory I cited, a CERT advisory, I might add, that was made before PHP even existed. Now you might not care about the security of your own machines but for myself I do think that dangerous advice should be countered where it is given. >> Quite what this has to do with Informix I'm not sure. > > Quite what this has to do with my post I'm not sure. I dont believe we have screaming hordes of Perl, Python, Tcl, Ruby, Scheme, Rebol, Rexx or Pike advocates here suggesting that their preferred language is a panacea to all problems - I see no reason why PHP should be any different. /J\\
On Fri, 19 May 2000 06:39:47 +0100, Andy Lennard Wrote: > In article <MPG.138f445d46e4d7c09896d7@news.xtra.co.nz>, Andrej Falout > <afalout@xtra.co.nz> writes >>In article <ShBvEBAwa4I5EwcF@kontron.demon.co.uk>, >>andy@kontron.demon.co.uk says... >>> For completeness, there's also tcl/tk >>> >>> Andy. >>> >> >>Can you run TCL/TK embeded in HTML ? > > I'm told you can, but it's not something I do. > <http://www.neosoft.com/neowebscript/> /J\\
Thanks, I'm gonna give the serial idea a shot. Andrej Falout wrote: > In article <ShBvEBAwa4I5EwcF@kontron.demon.co.uk>, > andy@kontron.demon.co.uk says... > > For completeness, there's also tcl/tk > > > > Andy. > > > > Can you run TCL/TK embeded in HTML ? > Can you access Informix database via TCL/TK ? > > -- > Yours, Andrej Falout, http://www.falout.com ICQ 7628616 ++64.21.607517 > #----------------------------------------------------------------- > globals "std_disclaimer.4gl" > > Ask yourself just one question: ¿ Qué más se puede hacer y aprender ? > - Propellerhead ReBirth RB-338 manual