Re: Where can I put the Password
| From: | Matt McClanahan | Date: | Tue, 30 May 2000 21:54:10 +0000 |
| Subject: | Re: Where can I put the Password | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-116@lists.php.net to get a copy of this message | ||
On Tue, 30 May 2000, MK wrote:
> If I hardwire the password and username for my MySQL database
> in the PHP script that is on my web server, does that pretty
> much mean that anybody can get into my database directly?
>
> If so, how do I go about being able to access my database
> without the security problem?
The primary issue when you put a user/pass in a web-visible PHP script is
that if for whatever reason the PHP engine on the server is disabled, that
script becomes accessible, unparsed.
Aside from going through the web server, you'd want to make sure the file
isn't in a world-readable ftp directory (See apache.org's recent exploit
for good reasons to watch out for this)
Generally, IMHO, a good place to put such files is somewhere in your
php_include path that isn't inside the web tree (Or ftp tree), and if
possible isn't world-readable (Though avoiding that isn't always possible)
Matt