Re: How secure is this?
| From: | Mukul Sabharwal | Date: | Sat, 30 Dec 2000 05:07:59 +0000 |
| Subject: | Re: How secure is this? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-32403@lists.php.net to get a copy of this message | ||
Well,
you could include() a file containing your database
definitions from a directory outside the visible
directory level.
and depending on how PHP is configured too (I
suppose), it would use Apache's security incase a
module, otherwise even you should have a look at
setuid. try searching on a list archive its' come up
before.
--- Sefton <c.sefton@xtra.co.nz> wrote: > I have setup
a page that accesses mysql. The page
> has to included the
> account login name and password to access the mysql
> database.
> Example...
>
> <?php
> $user = "username"; //actual username goes here
> $pass = "password"; //actual password goes here
>
> $db = mysql_connect("localhost", $user, $pass)OR
> DIE("Unable to connect
> to database");
> ?>
>
> If you get the idea.
>
> My concern is what if somebody can get to the source
> code. It could ruin me.
> I realise the php is a server side language, but is
> there any way that
> somebody could read this. If so how do i stop it? or
> is there another way to
> store my username & password that cannot be read.
>
> Please help
>
> Thanks
>
> Chris
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail:
> php-general-unsubscribe@lists.php.net
> For additional commands, e-mail:
> php-general-help@lists.php.net
> To contact the list administrators, e-mail:
> php-list-admin@lists.php.net
>
=====
To Find Out More About Me : http://mukul.tsx.org/
__________________________________________________
Do You Yahoo!?
Yahoo! Photos - Share your holiday photos online!
http://photos.yahoo.com/