Re: PHP and MYSQL Security`

From: Date: Mon, 28 Jan 2002 01:10:59 +0000
Subject: Re: PHP and MYSQL Security`
References: 1 2  Groups: php.db php.general 
Request: Send a blank email to php-db+get-16229@lists.php.net to get a copy of this message
At 16:59 -0800 1/27/02, Fred wrote:
If this file has a .php extension remote users will not have access to the variables because the file is parsed by php and they never see the actual file contents when requesting the document via the web. If you are concerned with users on localhost having access to the file, simply give it the correct permissions so that no one else has read access.
No so easy. The server itself must have read access. If other users on the local host can install scripts that the server executes, any of those scripts can read the text of your scripts. What then? You're hosed.
If you are concerned about web users having access, if, for example, the php parser crashed and apache tried to pass the file through without parsing, you can put the default server, user and pass variables in the php.ini file which is not in the document root for apache. Of course, this only works if all of your scripts use the same server, user and password. Fred Duky Yuen <duky@cable.a2000.nl> wrote in message news:3C549D5D.377A0E0F@cable.a2000.nl...
How can I secure my username and password? In 1 of my files, it contains the following:
     $conn = mysql_connect( "12.34.56.78", "username", "password");
     mysql_select_db("database",$conn);
What should I do, so people can't get this information? Duky
-- PHP Database Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net For additional commands, e-mail: php-db-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net


« previous php.db (#16229) next »