Re: Local security on username and password include file...(OCILogon)
| From: | rasmus@php.net | Date: | Thu, 01 Jan 1970 00:00:00 +0000 |
| Subject: | Re: Local security on username and password include file...(OCILogon) | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-1698@lists.php.net to get a copy of this message | ||
Fix your permissions and only make the file readable by the web server
user id.
On Wed, 2 Aug 2000, Serkan AKCIN wrote:
>
> Hi,
>
> Yesterday, Php worked and a simple code can query the oracle database.
>
> OCILogon("scott","tiger","a.b.com");
>
> worked.
>
> But this code was written in a oracle.inc file and has 744 permisson on
> Linux.
>
> Anyone has an account on my machine can see the plain text file,
> so my database's passwords is reachable by anyone on my linux box.
>
> grep Logon /var/lib/apache/htdocs/oracle.inc
>
> How can I secure my include files and let them executable by nobody from the
> www.
>
> Thanks to answers by now.
>
>
>
>
>
>
> --
> PHP Database Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net
> For additional commands, e-mail: php-db-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>