Re: PHP and MYSQL Security`
| From: | Alan McFarlane | Date: | Mon, 28 Jan 2002 01:48:10 +0000 |
| Subject: | Re: PHP and MYSQL Security` | ||
| References: | 1 | Groups: | php.db php.general |
| Request: | Send a blank email to php-db+get-16231@lists.php.net to get a copy of this message | ||
If you know you are running on an apache server, you could try using a
simple .htaccess file in a (say) etc directory which contains any or all
files you wish to secure.
ie:
/index.php
/etc/config.php
/etc/.htaccess
--index.php--------
<?php
include("etc/config.php");
...
?>
--etc/config.php--------
$config['db_host']="sql";
$config['db_name']="root";
$config['db_pass']="hooray";
?>
--etc/.htaccess--------
deny from all
And that's it!
Duky Yuen <duky@cable.a2000.nl> wrote in message
news:3C549D5D.377A0E0F@cable.a2000.nl...
> How can I secure my username and password? In 1 of my files, it contains
> the following:
>
> $conn = mysql_connect( "12.34.56.78", "username",
> "password");
> mysql_select_db("database",$conn);
>
> What should I do, so people can't get this information?
>
> Duky
>