note 14000 deleted from function.mysql-connect by sniper
| From: | sniper@php.net | Date: | Tue, 08 Jul 2003 12:21:03 +0000 |
| Subject: | note 14000 deleted from function.mysql-connect by sniper | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-51689@lists.php.net to get a copy of this message | ||
Note Submitter: hexar@hexar.net
----
A better way to protect your password/data with PHP and MySQL, if you don't need write access,
is to have a new user, such as "nobody" (which is often the default Apache user processing
your PHP anyway) who has read-only access to your database tables--and connect using nobody and no
password.
Another note: Say you want your script to write some files to one of your directories, but you
don't want the directory world-writable. Simply make the directory's group
"nobody" and chmod it 775. This way, "nobody" will have rw access, but nobody
else.
> It may be obvious, but scripts that
> use the mysql_connect function
> shouldn't be saved with a .txt
> extension if you want to keep your
> password secret.