CAM Posted August 31, 2011 Posted August 31, 2011 I keep seeing examples online where usernames and passwords are stored in plaintext using PHP script in a file such as connection.php. Is this safe if pulling website content from a database or will potential attackers be able to read the source-code?
Steve21 Posted August 31, 2011 Posted August 31, 2011 For all intense and purposes it's "generally" fine, as it's processed serverside before you see it etc. However any errors/misconfiguration blahblah it's in full view. aka, something not that important I wouldn't worry, something major no-no! Steve 1
ZeroHour Posted August 31, 2011 Posted August 31, 2011 As a general rule you try to keep those files out of the external access dirs (aka not inside /var/www/htdocs/ for example) but its fine really as long as your sever processes the php. The problem can occur if you break php and then .php files would be outputted raw thus readable. A far far bigger security hole is poorly locked down write permitted directories tbh. 1
CAM Posted August 31, 2011 Author Posted August 31, 2011 So how would I fix the break PHP problem and stop people looking at it? I know what you mean with write directories too, learned that the hard way! Gave up with those a long time ago as they are too much hassle to secure.
ZeroHour Posted August 31, 2011 Posted August 31, 2011 So how would I fix the break PHP problem and stop people looking at it? I know what you mean with write directories too, learned that the hard way! Gave up with those a long time ago as they are too much hassle to secure. Well dont give out root/admin and be careful when patching php really. The whole php engine would have to fail but if you simply move the connections.php file for example up a few dirs to a directory not accessible from port 80 that will prevent the issue. Also its not that hard to secure write dirs now with a few php tweaks tbh, I did it with the edugeek server.
webman Posted August 31, 2011 Posted August 31, 2011 A recommended method is to use ini files stored outside of the webroot, and use PHP methods to parse the ini files. The reason why this is different than including PHP files outside of the webroot, is that PHP files are included and processed as PHP files. If the config file contained a syntax error, you could still run the risk of exposing the contents. Like what happened to Tumblr a while ago. (See here and here). As always, there is never one hard and fast rule, and environments do differ quite a lot 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now