PHP security
| From: | Michelle | Date: | Fri, 20 Jul 2001 04:20:23 +0000 |
| Subject: | PHP security | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-58989@lists.php.net to get a copy of this message | ||
I need to store username and password for mysql in a file to be used by PHP.
I am concerned with PHP's security. Can anyone use showsource() to read php
source even if they are on a different server or they are spoofing my ip
address (hacking)?
If I put a file with the secure data in a directory outside the root
directory and include it in a PHP script, could someone use echo or
showsource() to view the file content making the data insecure?
Thanks!