Posted by Skijor on 12/10/06 19:06
> you could place it outside the Document Root or within a protected
> directory.
I did just that and I created an .htaccess file in the directory to
allow apache to protect it. I'm still a little insecure tho'. I can't
seem to get to the directory using browser so why the need to protect
it with .htaccess? My guess is that there will always be the potential
to get into this directory via url hacks. Also I was able to dowload
the file via ftp from the command line. How to stop that?
[Back to original message]
|