securityhole in php scripts

Hi all,
i played a bit with php3 and mysql to generate dynamic web-sites
but i think there's a security hole, because these scripts must
have read permission for others, and so every user on my system
can read the source, and the user/password for the mysql database

is there a way to protect these files?


