Re: MySQL connection
| From: | Tyler Longren | Date: | Tue, 07 Aug 2001 19:40:18 +0000 |
| Subject: | Re: MySQL connection | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-61686@lists.php.net to get a copy of this message | ||
If the SQL server is down how will he hack it? That's like hacking a
webserver that doesn't exist.
Tyler Longren
Captain Jack Communications
tyler@captainjack.com
www.captainjack.com
On Tue, 7 Aug 2001 21:35:58 +0200
"BRACK" <brak@nettaxi.com> wrote:
> I just wanned to bring the issue of security of MySQL connection:
>
> Let us imagine that SQL server was down for some hours (of
> course without us knowing it) and at the same hours our SQL site
> was visited by some kind of hacker, he can see on his screen all
> our SQL connection info like username, password, and database
> name. You may hide this information in different file than the file
> that your users open then the hacker will see something like
> "include("connect.inc");" or "require("connect.inc");"
> (of course IF
> server is down). So you may only imagine the consequences of
> this visit of the hacker. What can we do to protect our sensitive
> information if SQL server is down?
>
> Youri
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net