The best place to store it IMO is in the PHP file (regardless of whether you use it requireor includeit doesn’t matter) outside the root website, i.e. not directly available in the browser.
<?php
$db_server = "xyz";
$db_user = "def";
$db_password = "abc";
?>
If there is no access outside the web root
@Yacoby wrote this in his answer. He has deleted it since then, but it is definitely worth mentioning.
-, -. - .htaccess, Deny from All. . , , 403 Forbidden.