MySQL and password security
| From: | Andrew Watters | Date: | Wed, 06 Sep 2000 03:29:31 +0000 |
| Subject: | MySQL and password security | ||
| Groups: | php.db | ||
| Request: | Send a blank email to php-db+get-2638@lists.php.net to get a copy of this message | ||
I have a mySQL account at an ISP that I use with PHP. I've protected the
directory with the PHP files in it with .htaccess to restrict HTTP users.
The thing is, anyone with a legitimate account on the server can simply view
the PHP source of all of my files and obtain my mySQL username and password.
How can I put the username and password information in a separate file
accessible only by myself and the HTTP server? Someone told me I had to do
this, but I don't know exactly how to do it because I'm pretty new to PHP
and Linux in general. Can someone explain to me exactly the steps I need to
take?
Andrew Watters
awatters@ucla.edu