from what ive used it for, the web.config file is placed in a directory that you want the files to be password protected. then when any of those files is accessed, the web.config file automatically redirects you to a login form that you created. i do not know if its specific to asp.net, but i guess what im asking is if there is a way to do this with php, to password protect a section of a website and not another section, without having to log in multiple times... im sure there is, but i dont know what they are, heh.