Re: PHP and MYSQL Security`
| From: | Fred | Date: | Mon, 28 Jan 2002 00:59:31 +0000 |
| Subject: | Re: PHP and MYSQL Security` | ||
| References: | 1 | Groups: | php.db php.general |
| Request: | Send a blank email to php-db+get-16228@lists.php.net to get a copy of this message | ||
If this file has a .php extension remote users will not have access to the
variables because the file is parsed by php and they never see the actual
file contents when requesting the document via the web. If you are
concerned with users on localhost having access to the file, simply give it
the correct permissions so that no one else has read access.
If you are concerned about web users having access, if, for example, the php
parser crashed and apache tried to pass the file through without parsing,
you can put the default server, user and pass variables in the php.ini file
which is not in the document root for apache. Of course, this only works if
all of your scripts use the same server, user and password.
Fred
Duky Yuen <duky@cable.a2000.nl> wrote in message
news:3C549D5D.377A0E0F@cable.a2000.nl...
> How can I secure my username and password? In 1 of my files, it contains
> the following:
>
> $conn = mysql_connect( "12.34.56.78", "username",
> "password");
> mysql_select_db("database",$conn);
>
> What should I do, so people can't get this information?
>
> Duky
>