Re: Secure database connectivity?

From: Date: Fri, 20 Apr 2001 06:41:24 +0000
Subject: Re: Secure database connectivity?
References: 1 2  Groups: php.db 
Request: Send a blank email to php-db+get-8742@lists.php.net to get a copy of this message
file by FTP for example). If you're really paranoid, put the username/password outside your htroot into a separate file, say passwords.inc and include it into php with include('/secure/passwords.inc'), but this isn't really needed, and BTW, it won't make the connection method more secure, or insecure.
Perhaps I'm paranoid.. don't think it's bad. I would recommend putting it outside the htroot.. this will prevent people from seeing it if someone screws up the serverconfig.. Another thing.... I wouldn't call it password.inc.. if someone would gain access to your userdir they would first look for something with password or passwd in it.. give it an unrelated name.. I must agree that it won't make your PHP script more secure since it's parsed. But it's always a good thing to be carefull. Bye, B.

« previous php.db (#8742) next »