eg. If the path to the PDF docs is www.mycompany.com/PDFs/
and Joe user guesses that a file name is report1.pdf and then enters www.mycompany.com/PDFs/report1.pdf into his browser, he's gonna get the file. Right? I realise that someone guessing the directory name and the filename is not that high, but still. What do other people do about this?
Cheers, Clancy
From: Stephen Caudill <[EMAIL PROTECTED]> Reply-To: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: [wdvltalk] Re: Programmatical authentication for .htaccess Date: Fri, 13 Aug 2004 10:29:45 -0400
Forget .htaccess. Just don't put the files in the web root. Most hosting packages allow you at least some access to the file system outside of the web site's root, so stick the file there. Your scripts will still have access to it, but Joe Browser won't...
hth, Stephen
On Thu, 12 Aug 2004 18:18:29 -0700, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: <snip/> > Any other suggestions?
____ � The WDVL Discussion List from WDVL.COM � ____
To Join wdvltalk, Send An Email To: mailto:[EMAIL PROTECTED]
Send Your Posts To: [EMAIL PROTECTED]
To set a personal password send an email to [EMAIL PROTECTED] with the words: "set WDVLTALK pw=yourpassword" in the body of the email.
To change subscription settings to the wdvltalk digest version:
http://wdvl.internet.com/WDVL/Forum/#sub
________________ http://www.wdvl.com _______________________
You are currently subscribed to wdvltalk as: [EMAIL PROTECTED] To unsubscribe send a blank email to %%email.unsub%%
To unsubscribe via postal mail, please contact us at: Jupitermedia Corp. Attn: Discussion List Management 475 Park Avenue South New York, NY 10016
Please include the email address which you have been contacted with.
_________________________________________________________________
There�s never been a better time to get Xtra JetStream @ http://xtra.co.nz/jetstream
____ � The WDVL Discussion List from WDVL.COM � ____
To Join wdvltalk, Send An Email To: mailto:[EMAIL PROTECTED] Send Your Posts To: [EMAIL PROTECTED]
To set a personal password send an email to [EMAIL PROTECTED] with the words: "set WDVLTALK pw=yourpassword" in the body of the email.
To change subscription settings to the wdvltalk digest version:
http://wdvl.internet.com/WDVL/Forum/#sub
________________ http://www.wdvl.com _______________________
You are currently subscribed to wdvltalk as: [EMAIL PROTECTED] To unsubscribe send a blank email to [EMAIL PROTECTED]
To unsubscribe via postal mail, please contact us at: Jupitermedia Corp. Attn: Discussion List Management 475 Park Avenue South New York, NY 10016
Please include the email address which you have been contacted with.
