Apache HTTPD: How To Turn Off Index Listing in Directory & Sub-Directories; Protect WordPress wp-content ����ġ ������ : ���� ��Ͽ� ���丮�� �����ϴ� ��� �� ���� - ���丮 �鸰 - �������� ��ȣ�ϱ� wordpress
In Apache HTTPD server normally when you have no index or default page in a directory, a visitor may be served with a full list of files in that the directory. �Ϲ������� ����ġ ������ ��������� ��� �ε��� �Ǵ� �⺻ ���������� ���丮, �湮�� ���ֽ��ϴ� ������ ��ü ����� �����ϴ� ���丮�մϴ�. This could pose a serious security risk. �̰��� �ɰ��� ���� �������ֽ��ϴ�. It also exposes your files to the world at large, allowing them to be indexed by search engines and at the least pose privacy risk. ���� ������� ������ ���迡 ���� ũ��, �� �ֵ��� ������ ���ϴ� ����̵ǰ� �;� �˻� ���� �� �ּ��� ���� ���� ���� ��ȣ ��å �����մϴ�. There are well known Google hacks which exploit this feature. ���� hacks�� �ش��ϴ� �̹� �� �˷����ִ��� ����� �̿��մϴ�. To stop default directory listing, add this to the htaccess file. �⺻ ���丮 ����� �ߴ�, �߰� �̰��� htaccess �������մϴ�.
Options -Indexes �ɼ� - �ε���
This turns off index listing in the directory and all sub-directories under it. �� ����� ���� ���� ��Ͽ��� ���丮�� ��� ���� - ���丮 �ؿ� �װ��մϴ�.
Note: In many web servers, directory listing may be turned off by default. ��� ���� : ��κ��� �� ����, ���丮 ����� �⺻������ �����Ǿ��ֽ��ϴ�.
One of the vulnerable folder in wordpress is wp-content. �� �� �ϳ��� �鸰 - �������� wordpress ����� ����մϴ�. If you have a WordPress blog, check there to ensure that its content are not listed. wordpress ��αװ��ִ� ���, Ȯ���̵ǵ��� �� ������ ���� ���� �ʽ��ϴ�.
Filed under �ؿ� Computer Security ��ǻ�� ���� , Headline News ��� ���� ���� , How To �ϴ� ����� , Pro Blogging �������� ��α� , Web �� , Web 2.0 �� 2.0 , Web Services �� ���� , WordPress wordpress | |
| |
RSS 2.0 rss 2.0 | |
Trackback Ʈ���� this Article | �� ���� |
Email this Article ���� ������ ����
You may also like to read ������ ���� ���ֽ��ϴ� |




































