Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted
I keep seeing examples online where usernames and passwords are stored in plaintext using PHP script in a file such as connection.php. Is this safe if pulling website content from a database or will potential attackers be able to read the source-code?
Posted

For all intense and purposes it's "generally" fine, as it's processed serverside before you see it etc. However any errors/misconfiguration blahblah it's in full view.

 

aka, something not that important I wouldn't worry, something major no-no!

 

Steve

  • Thanks 1
Posted

As a general rule you try to keep those files out of the external access dirs (aka not inside /var/www/htdocs/ for example) but its fine really as long as your sever processes the php.

The problem can occur if you break php and then .php files would be outputted raw thus readable.

A far far bigger security hole is poorly locked down write permitted directories tbh.

  • Thanks 1
Posted

So how would I fix the break PHP problem and stop people looking at it?

 

I know what you mean with write directories too, learned that the hard way! Gave up with those a long time ago as they are too much hassle to secure.

Posted
So how would I fix the break PHP problem and stop people looking at it?

 

I know what you mean with write directories too, learned that the hard way! Gave up with those a long time ago as they are too much hassle to secure.

 

Well dont give out root/admin :D and be careful when patching php really. The whole php engine would have to fail but if you simply move the connections.php file for example up a few dirs to a directory not accessible from port 80 that will prevent the issue.

 

Also its not that hard to secure write dirs now with a few php tweaks tbh, I did it with the edugeek server.

Posted

A recommended method is to use ini files stored outside of the webroot, and use PHP methods to parse the ini files. The reason why this is different than including PHP files outside of the webroot, is that PHP files are included and processed as PHP files. If the config file contained a syntax error, you could still run the risk of exposing the contents.

 

Like what happened to Tumblr a while ago. (See here and here).

 

As always, there is never one hard and fast rule, and environments do differ quite a lot :)

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...