in reply to Re^4: Removing malicious HTML entities (now with more questions!)
in thread Removing malicious HTML entities (now with more questions!)
http://website.com/user/me/ should map to something like ~me/www/ and the password file should be located somewhere outside of ~me/www/ like ~me/data/, meaning somewhere no url can address.