Re: MySQL connection

From: Date: Wed, 08 Aug 2001 13:03:29 +0000
Subject: Re: MySQL connection
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-61814@lists.php.net to get a copy of this message
I mean he will know all your sensitive information to enter your SQL server in couple of hours when server will be up again. Youri On 7 Aug 2001, at 14:40, Tyler Longren wrote: > If the SQL server is down how will he hack it? That's like hacking a > webserver that doesn't exist. > > Tyler Longren > Captain Jack Communications > tyler@captainjack.com > www.captainjack.com > > > On Tue, 7 Aug 2001 21:35:58 +0200 > "BRACK" <brak@nettaxi.com> wrote: > > > I just wanned to bring the issue of security of MySQL connection: > > > > Let us imagine that SQL server was down for some hours (of > > course without us knowing it) and at the same hours our SQL site > > was visited by some kind of hacker, he can see on his screen all > > our SQL connection info like username, password, and database > > name. You may hide this information in different file than the file > > that your users open then the hacker will see something like > > "include("connect.inc");" or > > "require("connect.inc");" (of course IF > > server is down). So you may only imagine the consequences of > > this visit of the hacker. What can we do to protect our sensitive > > information if SQL server is down? > > > > Youri > > > > -- > > PHP General Mailing List (http://www.php.net/) > > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > > For additional commands, e-mail: php-general-help@lists.php.net > > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#61814) next »