On the first issue your path would probably be something like:
/home/domaincom/MPATT
there would not likely be a '.com' in it.
On the 2nd issue I don't know what to add, but I know that unless you need to hide attachments for a serious reason (like they are the source of revenue) that it really doesn't matter if you have an .htaccess file or not... just put an index.html file in the folder and no one will be able to browse your attachments- they'd need to know the full name and path to each to view them and so what if they do- unless you'll lose money somehow its no big deal.
|