Johannes Verelst wrote:
> 
> On Fri, 30 Nov 2001, Meritt James wrote:
> 
> > A couple of basic steps:
> >
> > 1. Don't put it on the system - ESPECIALLY in the ROOTDIR tree.
> > 2. Make !@#$#$@# sure your spiders.txt is right.
> 
> Hmm, don't you mean 'robots.txt'? Do you also know that real nasty spiders
> don't care about robots.txt? DO NOT EVER RELY ON THAT FILE FOR SECURITY!!!

yup.

> So, that said, what do you mean with the first point? Not putting a
> .htaccess on the filesystem?

No, don't put ANYTHING ANYWHERE if you want to be 100% sure of it not
getting away electronically.

If you are anyway, consider the risks.


-- 
James W. Meritt CISSP, CISA
Booz | Allen | Hamilton
phone: (410) 684-6566

Reply via email to