web site security: how to hide login info for mysql-connection
| From: | anders thoresson | Date: | Sun, 29 Jun 2003 09:04:04 +0000 |
| Subject: | web site security: how to hide login info for mysql-connection | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-153309@lists.php.net to get a copy of this message | ||
Hi,
At the moment I store username, password and database for my MySQL connections in a file called settings.php to avoid putting them in my php files direct. On a Linux server, what extra steps can I take to prevent others from accessing settings.php?
Somewhere, I've read that settings.php should be placed in a directory outside the html/php-directories. Today, my web directory is /home/anders/public_html and subdirectories to public_html. Should settings.php be placed in /home/anders/include?
--
anders thoresson