Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8447873
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 10, 20262026-06-10T10:17:03+00:00 2026-06-10T10:17:03+00:00

Here’s my basic setup… I have a website that will be used for employees

  • 0

Here’s my basic setup…

I have a website that will be used for employees to log in, and submit things like timesheet forms, purchases, etc. The website is written with some basic HTML and then has some PHP on the backend to run some SQL queries to pull/send some information to/from a Microsoft Access Database being hosted on the same server as the website.

My question is this… if somebody got an employees password to log onto the site, how easy would it be for them to view the contents of my database? I honestly have no intuition or clues to guide me here, so I’m asking for some help. Currently set up there is really no protection going on here, so if it is quite easy to access the database, I would like some pointers on how to secure it.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-10T10:17:04+00:00Added an answer on June 10, 2026 at 10:17 am

    if somebody got an employees password to log onto the site, how easy
    would it be for them to view the contents of my database?

    That all depends on the permissions and the connection strings. The same risk applies to the above scenario as what I posted below, but having valid credentials can certainly make it easier to get at the database.

    Even if they didn’t get someone’s password, it’s possible for someone to access your database if the website is vulnerable to SQL Injection.

    There are far too many variables to fully cover securing your database on this forum. But here are a few good places to start.

    • General overview of SQL Injection (one of the things you’ll be up against.)
    • OWASP Top 10 vulnerabilities list of 2010 (They update every few years, and the OWASP site is a must-read for security info)
    • IBM’s recommendations for secure PHP coding.

    Finally, I know you said you’re using PHP, not ASP.NET but I’m going to suggest the following link anyway. It goes way beyond just code, including threat modeling, common risks, etc. It is an excellent resource even if you’re not a .NET developer.

    • Building Secure ASP.NET Applications: Authentication, Authorization, and Secure Communication
    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Here's the basic setup: I have a thin bar at the top of a
Here is the problem that I am trying to solve. I have two folders
Here is my code (Say we have a single button on the page that
Here's a basic regex technique that I've never managed to remember. Let's say I'm
Here is the issue I am having: I have a large query that needs
Here's my scenario - I have an SSIS job that depends on another prior
Here's a coding problem for those that like this kind of thing. Let's see
Here is the scenario: I'm writing an app that will watch for any changes
Here is an object that I'd like to use with ng-repeat, but it's not
Here, I have one drop down with 3 value like 0, 1, 2 and

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.