MySQL and password security

From: Date: Wed, 06 Sep 2000 03:29:31 +0000
Subject: MySQL and password security
Groups: php.db 
Request: Send a blank email to php-db+get-2638@lists.php.net to get a copy of this message
I have a mySQL account at an ISP that I use with PHP. I've protected the directory with the PHP files in it with .htaccess to restrict HTTP users. The thing is, anyone with a legitimate account on the server can simply view the PHP source of all of my files and obtain my mySQL username and password. How can I put the username and password information in a separate file accessible only by myself and the HTTP server? Someone told me I had to do this, but I don't know exactly how to do it because I'm pretty new to PHP and Linux in general. Can someone explain to me exactly the steps I need to take? Andrew Watters awatters@ucla.edu

« previous php.db (#2638) next »