![]() |
|
Protecting the /inc directory. - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Design (https://sinister.li/Forum-Design) +--- Forum: Web Design (https://sinister.li/Forum-Web-Design) +--- Thread: Protecting the /inc directory. (/Thread-Protecting-the-inc-directory) |
Protecting the /inc directory. - Nefarious - 01-08-2014 This is honestly extremely easy and quick, it can also save you a lot of time and protect your forum. Create a .htaccess file in /inc/ I use filezilla. Now add this code to the file and save it. Code: deny from allNow try going to /inc, you should get a 403 error. POC: http://talkcode.net/inc/ RE: Protecting the /inc directory. - Aces - 01-08-2014 Actually if you just go to the config file for your domain you can edit a line so every directory is locked down so you can't do Directory Traversal . I have this on my sites. in Quote:/etc/apache2/sites-available/defaultchange "AllowOverride None" to "AllowOverride All". But doing it in .htaccess is nice too if you just have the inc folder that you want to be forbidden. :blackhat: RE: Protecting the /inc directory. - Nefarious - 01-08-2014 (01-08-2014, 12:35 PM)Aces Wrote: Actually if you just go to the config file for your domain you can edit a line so every directory is locked down so you can't do Directory Traversal . I have this on my sites. I'm unable to modify Apache files on shared hosting, or else they would all be locked. : P RE: Protecting the /inc directory. - Enenra - 01-08-2014 I don't think it's possible to look at the files inside the /inc/ folder though, so this would only help you preventing them from seeing the file names or am I wrong? RE: Protecting the /inc directory. - Nefarious - 01-08-2014 (01-08-2014, 06:31 PM)Enenra Wrote: I don't think it's possible to look at the files inside the /inc/ folder though, so this would only help you preventing them from seeing the file names or am I wrong? If they knew the name of a file inside the directory they could go directly to it. RE: Protecting the /inc directory. - Aces - 01-09-2014 (01-08-2014, 11:08 PM)Trey Wrote: If they knew the name of a file inside the directory they could go directly to it. You could be a little tricky about it though. You could make a code which displays a 404 code and change the HTTP status code to a 404. They wouldn't know if they found the right file or not.
RE: Protecting the /inc directory. - Kyou - 01-09-2014 Fast and easy, I've already done this too. It's just extra security. |