But, what's if, say, the PHP-Parser crashes (or a filename is changed) and
Apache returns the source. How is it simply possible to store passwords
somewhere a httpd-users won't see it? (e.g. in the includes-Folder, am I
And are session-variables send per post or does the next script reads it
from the session-file so nobody can't read them?

Jan Peuker

