In order to further harden a folder, for example an ‘uploads’ folder as used by WordPress, it maybe appropriate to block the execution of key file types. If you have a specific folder where content can be more easily written, blocking execution of script files will help reduce the chance of an attacker executing a script, even if they are able to upload it.
A lot of attacks automaticity identify vulnerable sites, and then attempt to exploit them. These attack scripts then essentially report a list of exploited sites, which are then used in a second stage, such as relaying spam email.
By creating a .htaccess file within this specific folder on your Apache web server, you can more tightly control what content is served.
1 2 3 4 |
<Files *.php> Order Deny,Allow Deny from all </Files> |
Hope this helps.
data:image/s3,"s3://crabby-images/6dbac/6dbacb61e14d4ef9170fa05e29ba856335fa79d5" alt="Share on Facebook Facebook"
data:image/s3,"s3://crabby-images/256b4/256b436de418725c9b8f6c2c29579b222b6a638f" alt="Share on Twitter twitter"
data:image/s3,"s3://crabby-images/af679/af679c771a2be06d1d9f53d0ca31d35cce4b6915" alt="Share on Google+ google_plus"
data:image/s3,"s3://crabby-images/b80de/b80de7e049c8e4d4d94f9c195251ad9cb5ebe0d6" alt="Share on Reddit reddit"
data:image/s3,"s3://crabby-images/2694b/2694b426c0706a2fedc18238092e3cd10cf0484e" alt="Pin it with Pinterest pinterest"
data:image/s3,"s3://crabby-images/b4f64/b4f64d0571202fe855ad5ea4db96270f7a29a590" alt="Share on Linkedin linkedin"
data:image/s3,"s3://crabby-images/1599a/1599a49a180b514d0f221cb58dee741c500c3787" alt="Share by email mail"
thank you, it helps me today.