web site security: how to hide login info for mysql-connection

From: Date: Sun, 29 Jun 2003 09:04:04 +0000
Subject: web site security: how to hide login info for mysql-connection
Groups: php.general 
Request: Send a blank email to php-general+get-153309@lists.php.net to get a copy of this message
Hi, At the moment I store username, password and database for my MySQL connections in a file called settings.php to avoid putting them in my php files direct. On a Linux server, what extra steps can I take to prevent others from accessing settings.php? Somewhere, I've read that settings.php should be placed in a directory outside the html/php-directories. Today, my web directory is /home/anders/public_html and subdirectories to public_html. Should settings.php be placed in /home/anders/include? -- anders thoresson

« previous php.general (#153309) next »