Re: MySQL and password security
| From: | Matt McClanahan | Date: | Wed, 06 Sep 2000 07:16:05 +0000 |
| Subject: | Re: MySQL and password security | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-2641@lists.php.net to get a copy of this message | ||
On Tue, 5 Sep 2000, Andrew Watters wrote:
> I have a mySQL account at an ISP that I use with PHP. I've protected the
> directory with the PHP files in it with .htaccess to restrict HTTP users.
> The thing is, anyone with a legitimate account on the server can simply view
> the PHP source of all of my files and obtain my mySQL username and password.
> How can I put the username and password information in a separate file
> accessible only by myself and the HTTP server? Someone told me I had to do
> this, but I don't know exactly how to do it because I'm pretty new to PHP
> and Linux in general. Can someone explain to me exactly the steps I need to
> take?
Generally, it's a good idea to keep any login/password information in a
file outside your web root. Trusting .htaccess isn't really enough, imho,
because it can be disabled with a single httpd.conf edit (Be it
intentional or accidental). Put the variables with the login/password
info somewhere in your include_path (Or not, it's just a convinience
issue) and restrict that path as much as possible. 'Other' users don't
need access to it, ideally it will be owned by yourself (Or whoever is
responsible for development) and group-readable by the group which the
http user is in (nobody, www-data, websites, whatever)
HTH,
Matt