Sinisterly
Protecting the /inc directory. - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Design (https://sinister.li/Forum-Design)
+--- Forum: Web Design (https://sinister.li/Forum-Web-Design)
+--- Thread: Protecting the /inc directory. (/Thread-Protecting-the-inc-directory)



Protecting the /inc directory. - Nefarious - 01-08-2014

This is honestly extremely easy and quick, it can also save you a lot of time and protect your forum.

Create a .htaccess file in /inc/ I use filezilla.

Now add this code to the file and save it.

Code:
deny from all

Now try going to /inc, you should get a 403 error.

POC: http://talkcode.net/inc/


RE: Protecting the /inc directory. - Aces - 01-08-2014

Actually if you just go to the config file for your domain you can edit a line so every directory is locked down so you can't do Directory Traversal . I have this on my sites.

in
Quote:/etc/apache2/sites-available/default
change "AllowOverride None" to "AllowOverride All". But doing it in .htaccess is nice too if you just have the inc folder that you want to be forbidden. :blackhat:


RE: Protecting the /inc directory. - Nefarious - 01-08-2014

(01-08-2014, 12:35 PM)Aces Wrote: Actually if you just go to the config file for your domain you can edit a line so every directory is locked down so you can't do Directory Traversal . I have this on my sites.

in change "AllowOverride None" to "AllowOverride All". But doing it in .htaccess is nice too if you just have the inc folder that you want to be forbidden. :blackhat:

I'm unable to modify Apache files on shared hosting, or else they would all be locked. : P


RE: Protecting the /inc directory. - Enenra - 01-08-2014

I don't think it's possible to look at the files inside the /inc/ folder though, so this would only help you preventing them from seeing the file names or am I wrong?


RE: Protecting the /inc directory. - Nefarious - 01-08-2014

(01-08-2014, 06:31 PM)Enenra Wrote: I don't think it's possible to look at the files inside the /inc/ folder though, so this would only help you preventing them from seeing the file names or am I wrong?

If they knew the name of a file inside the directory they could go directly to it.


RE: Protecting the /inc directory. - Aces - 01-09-2014

(01-08-2014, 11:08 PM)Trey Wrote: If they knew the name of a file inside the directory they could go directly to it.

You could be a little tricky about it though. You could make a code which displays a 404 code and change the HTTP status code to a 404. They wouldn't know if they found the right file or not. Smile


RE: Protecting the /inc directory. - Kyou - 01-09-2014

Fast and easy, I've already done this too. It's just extra security.