MySQL Development
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
User Name:
Password:
Remember me
 
Go Back   Dev Articles Community ForumsDatabasesMySQL Development

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Display Modes
 
Unread Dev Articles Community Forums Sponsor:
Stay one step ahead of the competition. Evaluate and give feedback on some of the hottest web development tools on the market today. Make your opinion heard! Click Here
  #1  
Old November 15th, 2003, 01:09 PM
lgayk lgayk is offline
Junior Member
Dev Articles Newbie (0 - 499 posts)
 
Join Date: Nov 2003
Posts: 1 lgayk User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
PHP / MySQL authentication question

Hello,

I've been building a small CMS for a collegiate organization that I'm involved in and have run into a small problem. The CMS will be hosted on our school's public web server meaning that everyone in the university community has shell access to the machine. In all past php related projects, I've had the liberty to have the database password in clear text in my code, but I'm afraid that doing so on a machine with 20,000 user accounts is just asking for trouble (anyone with half a brain and too much free time can cd into my public_html directory and cat my code.) Does anyone have any ideas on how I could secure this password?

Thanks.

P.S - I don't have root access and the sysadmins are usually unwilling to make server configuration changes.

Reply With Quote
  #2  
Old November 16th, 2003, 03:39 AM
laidbak laidbak is offline
you know how we do
Dev Articles Novice (500 - 999 posts)
 
Join Date: Jun 2002
Location: In Tha IE -- San Bernardino COUNTY
Posts: 788 laidbak User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 4 m 2 sec
Reputation Power: 7
Send a message via ICQ to laidbak Send a message via AIM to laidbak Send a message via MSN to laidbak Send a message via Yahoo to laidbak
You should keep included files such as this one outside your public_html directory.

Nobody but you should be able to do a directory list on your home directory, so anywhere under there besides public_html should be fine.

If you still have problems you probably don't want to host any site there anyhow.

Reply With Quote
  #3  
Old November 16th, 2003, 03:39 AM
laidbak laidbak is offline
you know how we do
Dev Articles Novice (500 - 999 posts)
 
Join Date: Jun 2002
Location: In Tha IE -- San Bernardino COUNTY
Posts: 788 laidbak User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 4 m 2 sec
Reputation Power: 7
Send a message via ICQ to laidbak Send a message via AIM to laidbak Send a message via MSN to laidbak Send a message via Yahoo to laidbak
You should keep included files such as this one outside your public_html directory.

Nobody but you should be able to do a directory list on your home directory, so anywhere under there besides public_html should be fine.

If you still have problems you probably don't want to host any site there anyhow.

Reply With Quote
Reply

Viewing: Dev Articles Community ForumsDatabasesMySQL Development > PHP / MySQL authentication question


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 5 hosted by Hostway