Hi All,
i found that :
"In order to reduce a web application attack surface, only web
application pages should be kept on the web directory and any other
files should be removed to any other local folders."
my questions are:
1- is that true?? and why??
2- what are exactly the file extensions that are allowed to be left on
the default web directory??
3- what are the type of files that are considered to be vurneable????
finally, if anyone one has any reference for such a topic, i'll be
happy receiving it :)
thanx for ur help and reply :)