If the permissions of your CGI script gets minced in some way, the whole world might have read access to the source code, and to your db passwords.
Put your db passwords in a file outside of your webroot, and at least if the permissions are wrong, it's likely to 'only' be other users of the machine that will get to see your passwords, not everyone with a web browser.
Cheers.
BazB
In reply to Re: Possible CGI/database security issue?
by BazB
in thread Possible CGI/database security issue?
by mephit
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |