mirror of
https://github.com/myronblair/do-server-config
synced 2026-07-28 13:32:58 -05:00
[orbis] Weekly backup 2026-07-07 — 318 files changed, 48597 insertions(+), 7 deletions(-)
This commit is contained in:
@@ -0,0 +1,21 @@
|
||||
<Files db.php>
|
||||
Order deny,allow
|
||||
Deny from all
|
||||
</Files>
|
||||
|
||||
RewriteEngine On
|
||||
RewriteRule ^db\.php$ - [F,L]
|
||||
RewriteCond %{REQUEST_URI} ^/db\.php$
|
||||
RewriteRule .* - [F,L]
|
||||
|
||||
# .git/ was found directly downloadable (leaked GitHub PAT) - same class of
|
||||
# issue found and fixed on sibling sites this session.
|
||||
RewriteCond %{REQUEST_URI} ^/\.git
|
||||
RewriteRule .* - [F,L]
|
||||
|
||||
# uploads/ (customer license/insurance docs) must never be directly downloadable -
|
||||
# same Order/Deny-doesn't-work-on-OpenLiteSpeed gotcha as .git above. Docs are
|
||||
# served only through view-doc.php / admin/view-doc.php, which read by filesystem
|
||||
# path via readfile() - blocking direct URL access here doesn't break that flow.
|
||||
RewriteCond %{REQUEST_URI} ^/uploads/
|
||||
RewriteRule .* - [F,L]
|
||||
Reference in New Issue
Block a user