Posted by: Anonymous Coward
on March 25, 2005 12:17 AM
I'm sorry to see that you were bitten by this exploit, but I'm also surprised that you made web statistics publicly available. I'm no fan of security through obscurity, but web statistics can reveal information about a site that would invite disaster if indexed by a search engine, including private pages, other web apps, and sometimes even arguments passed in URLs. The use of basic HTTP authentication might have prevented this episode.
Best Practice - Restrict access to web stats
Posted by: Anonymous Coward on March 25, 2005 12:17 AM#