Is this secure enough?
| From: | Dave Jones | Date: | Sun, 20 Aug 2000 21:14:29 +0000 |
| Subject: | Is this secure enough? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-12672@lists.php.net to get a copy of this message | ||
I jsut finished my first real php site and want to make sure there's
nothing I left out as far as unauthorized people getting to my php code
and MySQL data.
I'm on a shared server (virtual domains on a web host). As far as I
know the domains are kept from looking at each other with .htaccess
(which I know isn't perfect, but should stop casual snoops).
I have the php code that connects to the database (and contains my
MySQL username, password, and database name) inside an include file
which is stored in a subdirectory of my cgi-bin directory, and that
subdirectory is password protected (again, .htaccess). The rest of the
php is just in the pages spread throughout the web accessable folders.
The only other thing I could come up with is to put all of the page
content (for all pages) inside include files that are in a password
protected folder and the public files contain nothing but one include
statement each, but this seems to be getting too paranoid.
Since this is a shared server, I don't have access to configuring php
or MySQL (and the host is too large and accounts too cheap to ask for
anything special in that vein). Is this about as good as I can do for
security?
...Dave
--------------------
To send e-mail to me replace the
domain name with djdesign.com
The phony "anti.spam" domain
is used to fool newsgroup e-mail
address harvestor 'bots.
----------------------