> There are also sites that will let you view all of your directory trees, > which a server could easily see all of your files. Which do you think is > more scary?
There was a post about this on one of the other Security Focus mailing lists a few days ago... that is simply a small bit of HTML or JavaScript that makes your computer display the contents of you C:\ drive ; nothing is accessible by the website. DoPo
