Re: MySQL and password security

From: Date: Wed, 06 Sep 2000 07:16:05 +0000
Subject: Re: MySQL and password security
References: 1  Groups: php.db 
Request: Send a blank email to php-db+get-2641@lists.php.net to get a copy of this message
On Tue, 5 Sep 2000, Andrew Watters wrote: > I have a mySQL account at an ISP that I use with PHP. I've protected the > directory with the PHP files in it with .htaccess to restrict HTTP users. > The thing is, anyone with a legitimate account on the server can simply view > the PHP source of all of my files and obtain my mySQL username and password. > How can I put the username and password information in a separate file > accessible only by myself and the HTTP server? Someone told me I had to do > this, but I don't know exactly how to do it because I'm pretty new to PHP > and Linux in general. Can someone explain to me exactly the steps I need to > take? Generally, it's a good idea to keep any login/password information in a file outside your web root. Trusting .htaccess isn't really enough, imho, because it can be disabled with a single httpd.conf edit (Be it intentional or accidental). Put the variables with the login/password info somewhere in your include_path (Or not, it's just a convinience issue) and restrict that path as much as possible. 'Other' users don't need access to it, ideally it will be owned by yourself (Or whoever is responsible for development) and group-readable by the group which the http user is in (nobody, www-data, websites, whatever) HTH, Matt

« previous php.db (#2641) next »