protect your wordpress folders!

Discussion in 'WordPress' started by countolaf, May 11, 2009.

  1. #1
    its very alarming but yesterday i was visiting some blogs (blogs w/less than 100,000 alexa rank) and 7/10 of them have their wordpress subfolders browsable w/c means anyone can view the url 'blogname.com/wp-content/plugins' or 'blogname.com/wp-content/themes' This is bad because hackers can pretty much exploit it and then hack your blog, or people could easily get your themes and stuffs inside your folders.

    The simplest solution is to put "options - indexes" in your .htaccess file...
     
    countolaf, May 11, 2009 IP
  2. Plato

    Plato Active Member

    Messages:
    202
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    75
    #2
    Plato, May 11, 2009 IP
  3. countolaf

    countolaf Active Member

    Messages:
    662
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    58
    #3
    hey plato thanks! not aware of that plugin..
     
    countolaf, May 11, 2009 IP
  4. Plato

    Plato Active Member

    Messages:
    202
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    75
    #4
    There are a few more, but that one is especially good imo.

    What exactly would you put in your htaccess to protect your files?
     
    Plato, May 11, 2009 IP
  5. countolaf

    countolaf Active Member

    Messages:
    662
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    58
    #5
    options - indexes

    that makes every folder unaccessible
     
    countolaf, May 11, 2009 IP
  6. Plato

    Plato Active Member

    Messages:
    202
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    75
    #6
    That's easy enough. Would it go just like that without any extra characters?
     
    Plato, May 11, 2009 IP
  7. theivo

    theivo Well-Known Member

    Messages:
    238
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    105
    #7
    put this

    Options All -Indexes
    Code (markup):
    in your .htaccess file
     
    theivo, May 11, 2009 IP