You cannot rule out that a web block has been hacked. In addition, you do not want network administrators to know database passwords.
You need to remember that configuration files cannot be retrieved by the browser just because the .config
extension is in the list of restrictions in IIS metadata. Perhaps they can be obtained from the server in another way or a problem with the wrong configuration may allow them to be downloaded.
source share