Re: Where can I put the Password

From: Date: Tue, 30 May 2000 21:54:10 +0000
Subject: Re: Where can I put the Password
References: 1  Groups: php.db 
Request: Send a blank email to php-db+get-116@lists.php.net to get a copy of this message
On Tue, 30 May 2000, MK wrote: > If I hardwire the password and username for my MySQL database > in the PHP script that is on my web server, does that pretty > much mean that anybody can get into my database directly? > > If so, how do I go about being able to access my database > without the security problem? The primary issue when you put a user/pass in a web-visible PHP script is that if for whatever reason the PHP engine on the server is disabled, that script becomes accessible, unparsed. Aside from going through the web server, you'd want to make sure the file isn't in a world-readable ftp directory (See apache.org's recent exploit for good reasons to watch out for this) Generally, IMHO, a good place to put such files is somewhere in your php_include path that isn't inside the web tree (Or ftp tree), and if possible isn't world-readable (Though avoiding that isn't always possible) Matt

« previous php.db (#116) next »