...applications and can possibly be read to obtain names and passwords specific to the application. By default, IIS will not allowweb.config files to be served to clients, so this information normally cannot be accessed. However, developers should...
http://documents.iss.net/whitepapers/asp_net_whitepaper.pdf