It’s good for you to verify sha-1 checksum whenever you downloaded files from Google Code. By performing SHA-1 checksum verification, you will be able to tell if the file is orignal and it’s not being compromised. Of course, not all the website provide sha-1 checksum value, but they do provide, it’s good for us to perform the verification.

To verify a SHA-1 checksum in Mac OS X, follow the steps below:-
Continue reading How to verify SHA-1 checksum in Mac OS X? »

It’s a good practice to block visitor access to file types that is not being used in web server. You can configure .htaccess to block access to specific file types (eg: inc, bak, log, sh). It’s common for webmaster to edit files at the server and rename the old filename to .bak. If your file contain sensitive information like login credentials, then your info will be expose to public. 