    Zeek Guest

    I have a Global.asa file the contains Application-scoped variables with SQL Server database information (ConnectString, Timeout, etc), but when the file is entered into the Address bar,on the browser, with a +.htr on the end, you can see all of my source script WHICH INCLUDES THE USER NAME AND PASSWORD for the database! Obviously, this is not acceptable. Any help would be appreciated!!

    James W Guest

    Apply the patch found here:<BR><BR><BR>which came from 4guys security section:<BR>

