13.09.2016 Views

PHP and MySQL Web Development 4th Ed-tqw-_darksiderg

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Securing Your Code<br />

375<br />

Although this is convenient, it is slightly insecure in that if crackers were to get their<br />

h<strong>and</strong>s on our .php file, they would have immediate access to our database with the full<br />

permissions that the user bob has.<br />

Better would be to put the username <strong>and</strong> password in a file that is not in the document<br />

root of the web application, <strong>and</strong> include it in our script, as follows:<br />

<br />

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!