spageforum
Starting Member
Australia
29 Posts |
Posted - 06 July 2001 : 09:35:34
|
I just insltalled the forum, and am new to .asp, so this might be a silly question.
Can someone download/read the config.asp from the forum folder, and find the location of the database file?
I assume that the database file is the only place where passwords are recorded. Is this right?
I have installed the db file as a password protected (but database writable) file in another location of the website. Any thoughts? Thanks.
Edited by - spageforum on 06 July 2001 09:38:34 |
|
Doug G
Support Moderator
USA
6493 Posts |
Posted - 06 July 2001 : 10:30:21
|
A user cannot see the source code of an asp file unless there is a misconfiguration or a problem with the web server. asp files processed by a dll on the server when requested.
If your web server is misconfigured so that asp files don't go to the asp dll, or if the folder with the files isn't marked as script executable, then the files will be downloadable.
There was a bug in IIS a couple years ago that allowed a hack to the asp code, so if you're on an older IIS server make sure it's updated to the latest service packs.
====== Doug G ====== |
|
|