RE: [PHP] How secure is this?
| From: | WreckRman2 | Date: | Fri, 29 Dec 2000 22:56:41 +0000 |
| Subject: | RE: [PHP] How secure is this? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-32223@lists.php.net to get a copy of this message | ||
I use the following code to connect and the only way to get the
username/password is if you have access to the raw file.
$connection = mysql_connect ("localhost", "username", "password");
if ($connection == false){
echo mysql_errno().": ".mysql_error()."<BR>";
exit;
}
-----Original Message-----
From: Sefton [mailto:c.sefton@xtra.co.nz]
Sent: Friday, December 29, 2000 5:22 PM
To: php-general@lists.php.net
Subject: [PHP] How secure is this?
I have setup a page that accesses mysql. The page has to included the
account login name and password to access the mysql database.
Example...
<?php
$user = "username"; //actual username goes here
$pass = "password"; //actual password goes here
$db = mysql_connect("localhost", $user, $pass)OR DIE("Unable to connect
to database");
?>
If you get the idea.
My concern is what if somebody can get to the source code. It could ruin me.
I realise the php is a server side language, but is there any way that
somebody could read this. If so how do i stop it? or is there another way to
store my username & password that cannot be read.
Please help
Thanks
Chris
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net