Brent Dax (brentdax) wrote,
Brent Dax

Users are too damn clever.

I just found out that three Filespace users have .htaccess files like this one:

<FilesMatch avatar.gif> 
SetHandler application/x-httpd-php 
Two others have files like that called ".htaccess.txt"--I didn't even know that worked.

For the non-technically-inclined, that means they worked out how to get Filespace to run a file as a PHP script. I'll have to disable htaccess files, of course...

However, all three of them were using it to do avatar rotation, which suggests that I should do something to help them. about this?
