PHP security

From: Date: Fri, 20 Jul 2001 04:20:23 +0000
Subject: PHP security
Groups: php.general 
Request: Send a blank email to php-general+get-58989@lists.php.net to get a copy of this message
I need to store username and password for mysql in a file to be used by PHP. I am concerned with PHP's security. Can anyone use showsource() to read php source even if they are on a different server or they are spoofing my ip address (hacking)? If I put a file with the secure data in a directory outside the root directory and include it in a PHP script, could someone use echo or showsource() to view the file content making the data insecure? Thanks!

« previous php.general (#58989) next »