in reply to RE: (4) directory list
in thread directory list

Sure there is. Suppose you have a directory of images that only registered users of your site should be able to see. You've just bypassed all your webserver's authentication and authorization mechanisms!

And even if you, Adam, understand the limitations, you didn't document them, leaving the onlookers with a potentially dangerous security hole in their environment.

No, I don't think I'm being an alarmist. What you posted is dangerous if cargo-culted. And believe me... it will end up where you least expect it.

-- Randal L. Schwartz, Perl hacker