Re: How secure is this?

From: Date: Sat, 30 Dec 2000 05:07:59 +0000
Subject: Re: How secure is this?
Groups: php.general 
Request: Send a blank email to php-general+get-32403@lists.php.net to get a copy of this message
Well, you could include() a file containing your database definitions from a directory outside the visible directory level. and depending on how PHP is configured too (I suppose), it would use Apache's security incase a module, otherwise even you should have a look at setuid. try searching on a list archive its' come up before. --- Sefton <c.sefton@xtra.co.nz> wrote: > I have setup a page that accesses mysql. The page > has to included the > account login name and password to access the mysql > database. > Example... > > <?php > $user = "username"; //actual username goes here > $pass = "password"; //actual password goes here > > $db = mysql_connect("localhost", $user, $pass)OR > DIE("Unable to connect > to database"); > ?> > > If you get the idea. > > My concern is what if somebody can get to the source > code. It could ruin me. > I realise the php is a server side language, but is > there any way that > somebody could read this. If so how do i stop it? or > is there another way to > store my username & password that cannot be read. > > Please help > > Thanks > > Chris > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: > php-general-unsubscribe@lists.php.net > For additional commands, e-mail: > php-general-help@lists.php.net > To contact the list administrators, e-mail: > php-list-admin@lists.php.net > ===== To Find Out More About Me : http://mukul.tsx.org/ __________________________________________________ Do You Yahoo!? Yahoo! Photos - Share your holiday photos online! http://photos.yahoo.com/

« previous php.general (#32403) next »