Contact: Web / Voice / Email / Tips
Simple Thoughts Blog - Java and Web Technologies

Simple solutions for complex problems.

 

Apache HTTPD: How To Turn Off Index Listing in Directory & Sub-Directories; Protect WordPress wp-content

April 13th, 2008 by Angsuman Chakraborty

In Apache HTTPD server normally when you have no index or default page in a directory, a visitor may be served with a full list of files in that the directory. This could pose a serious security risk. It also exposes your files to the world at large, allowing them to be indexed by search engines and at the least pose privacy risk. There are well known Google hacks which exploit this feature. To stop default directory listing, add this to the htaccess file.

Options -Indexes

This turns off index listing in the directory and all sub-directories under it.

Note: In many web servers, directory listing may be turned off by default.

One of the vulnerable folder in wordpress is wp-content. If you have a WordPress blog, check there to ensure that its content are not listed.


Filed under Computer Security, Headline News, How To, Pro Blogging, Web, Web 2.0, Web Services, WordPress | | RSS 2.0 | Trackback this Article | Email this Article

You may also like to read

»How To Use .htaccess to Prevent Apache HTTPD Directory Listing
»How To Run PHP in HTML Pages
»Compressing php output with wp-cache2 WordPress Plugin
»How To Migrate Mantis Defect Tracking System From Windows To Linux / Fedora Core 6
»Tomcat 5.5 with Apache 2.0 Integration in 5 Simple Steps
»How To Enable / Use .htaccess / Nice permalinks in Apache Web Server on Windows
»How To Properly Display Multi-Lingual Sites
»How To Configure PHP 5 With Apache 2 On Windows in 2 Minutes
»Security Vulnerability: Firewall Site Exposes Sensitive Data Through phpMyAdmin
»Cool SEO Redirection Feature in WordPress 2.3.x
»WordPress Dashboard Blank Page Display Solution
»Angsuman's WordPress 2.0 / 1.5.x Dashboard Replacement: How to Trim The Fat Resource Hogging WordPress Admin Dashboard
»How To Use Apache HTTP WebDav Server With Windows XP Explorer
»How To Test PHP Support In Apache HTTP Server
»WordPress Plugin: Angsuman's Referrer Bouncer

Looking forward to hear your thoughts.



Please enter the code shown below ( to verify that you are human ) before you click Submit Comment.

No. 1 method to ethically increase your blog traffic and reach.

Translate

Translate to EnglishÜbersetzen Sie zum Deutsch/GermanPřeložit do Čech/CzechOversætte hen til Dansk/DanishKääntää jotta Finnish/FinnishLefordít -hoz Magyar/HungarianÞýða til Íslenska/IcelandicTraducir a Latinoamericano Español/Latin American Spanishtagapagsalin sa Filipino/FilipinoTłumaczyć wobec Polski/PolishA traduce la spre Român/RomanianPrevesti za Srpski/Serbiantolmačiti v slovenski/SlovenianÖversätta till Svensk/SwedishChyfieitha at Cymraeg/Welshtercüme etmek -e doğru Türk/TurkishPrevesti to Hrvatski/CroatianПревеждам към Българин/BulgarianTraduzca al Español/SpanishTraduisez au Français/FrenchTraduca ad Italiano/ItalianTraduza ao Português/Portuguese日本語に翻訳しなさい /Japanese한국어에게 번역하십시오/Korean中文翻译/Chinese Simplifiedترجمة الى العربية/ArabicVertaal aan het Nederlands/DutchΜεταφράστε στα ελληνικά/GreekПереведите к русскому/RussianOversetter til Norsk/Norwegian中文翻译/Chinese TraditionalTraduzir a Língua portuguesa brasileira/Brazilian PortugueseReddo ut Latin/Latin

Taragana Network

»Ctrl-S
»Enterprise Blog
»Free Book on Eye Care by Natural Therapy
»Health Care Blog
»Hot Computer Jobs Blog
»Pet Care & Grooming News and Tips
»Phil Law Blog
»Taragana - Software Outsourcing
»The Angsuman Chakraborty Blog
»The Diabetes Cure Blog
»The Eye Treatment Blog
»The Stem Cell Blog
»Weblog Hosting Blog
"The release of atom power has changed everything except our way of thinking...the solution to this problem lies in the heart of mankind. If only I had known, I should have become a watchmaker." - Albert Einstein