Login Register






Protecting the /inc directory. filter_list
Author
Message
Protecting the /inc directory. #1
This is honestly extremely easy and quick, it can also save you a lot of time and protect your forum.

Create a .htaccess file in /inc/ I use filezilla.

Now add this code to the file and save it.

Code:
deny from all

Now try going to /inc, you should get a 403 error.

POC: http://talkcode.net/inc/

Reply

RE: Protecting the /inc directory. #2
Actually if you just go to the config file for your domain you can edit a line so every directory is locked down so you can't do Directory Traversal . I have this on my sites.

in
Quote:/etc/apache2/sites-available/default
change "AllowOverride None" to "AllowOverride All". But doing it in .htaccess is nice too if you just have the inc folder that you want to be forbidden. :blackhat:
Tutorials & Releases:

[Tutorial] PHP: Getting Started
[Release] [HF Cool List] Are you cool?


PM me if you need any PHP help.

Reply

RE: Protecting the /inc directory. #3
(01-08-2014, 12:35 PM)Aces Wrote: Actually if you just go to the config file for your domain you can edit a line so every directory is locked down so you can't do Directory Traversal . I have this on my sites.

in change "AllowOverride None" to "AllowOverride All". But doing it in .htaccess is nice too if you just have the inc folder that you want to be forbidden. :blackhat:

I'm unable to modify Apache files on shared hosting, or else they would all be locked. : P

Reply

RE: Protecting the /inc directory. #4
I don't think it's possible to look at the files inside the /inc/ folder though, so this would only help you preventing them from seeing the file names or am I wrong?

Reply

RE: Protecting the /inc directory. #5
(01-08-2014, 06:31 PM)Enenra Wrote: I don't think it's possible to look at the files inside the /inc/ folder though, so this would only help you preventing them from seeing the file names or am I wrong?

If they knew the name of a file inside the directory they could go directly to it.

Reply

RE: Protecting the /inc directory. #6
(01-08-2014, 11:08 PM)Trey Wrote: If they knew the name of a file inside the directory they could go directly to it.

You could be a little tricky about it though. You could make a code which displays a 404 code and change the HTTP status code to a 404. They wouldn't know if they found the right file or not. Smile
Tutorials & Releases:

[Tutorial] PHP: Getting Started
[Release] [HF Cool List] Are you cool?


PM me if you need any PHP help.

Reply

RE: Protecting the /inc directory. #7
Fast and easy, I've already done this too. It's just extra security.
[Image: 7yW1UHU.jpg]

Reply