security and establishing DB connection

From: Date: Thu, 24 Aug 2000 08:50:39 +0000
Subject: security and establishing DB connection
Groups: php.db 
Request: Send a blank email to php-db+get-2315@lists.php.net to get a copy of this message
I am building some robust tools for site administration, using PHP mod and MySQL as principle tools with Apache and a free *nix. Currently I require('include/database.php') in each page that requires database interaction. That file consists of: <? $db = dbname; static $connection; if (!isset($connection)) { $connection = mysql_connect("localhost","dbuser","dbpword"); $setdb = mysql_select_db($db); } ?> Now because include/ is inside my doc_root and is world readable, it is conceivable that it could be read by anyone on the server and is particularly vulnerable if a hole were exploited which returned the php code uninterpreted. I don't want the username and password to a user account on the database to be advertised like this (dbuser only has minimal rights anyway, but damage could be done if data in the DB was compromised). The only thing I can think of is to chgrp the database.php file to nobody and chmod the file 640 as this prevents user accounts on the server from reading the file (other than the file owner and nobody who will still be able to read it obviously), but I am still not sleeping well at night because it doesn't address the original problem of uninterpreted php code. Any suggestions? Thanks --Steve

« previous php.db (#2315) next »