/
.htaccess
executable file
·87 lines (77 loc) · 3.45 KB
/
.htaccess
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
##
# Flextype - Hybrid Content Management System with the freedom of a headless CMS
# and with the full functionality of a traditional CMS!
#
# Copyright (c) Sergey Romanenko (https://awilum.github.io)
#
# Licensed under The MIT License.
#
# For full copyright and license information, please see the LICENSE
# Redistributions of files must retain the above copyright notice.
##
## Common PHP Overrides
#
# Some of the most common settings that can (sometimes) be overridden.
# php_value memory_limit 256M
# php_value post_max_size 16M
# php_value max_execution_time 90
# php_value max_input_time 120
# php_value upload_max_filesize 16M
# php_value realpath_cache_size 16M
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
## Begin - Exploits
# If you experience problems on your site block out the operations listed below
# This attempts to block the most common type of exploit `attempts` to Flextype
#
# Block out any script trying to use twig tags in URL.
RewriteCond %{REQUEST_URI} ({{|}}|{%|%}) [OR]
RewriteCond %{QUERY_STRING} ({{|}}|{%25|%25}) [OR]
# Block out any script trying to base64_encode data within the URL.
RewriteCond %{QUERY_STRING} base64_encode[^(]*\([^)]*\) [OR]
# Block out any script that includes a <script> tag in URL.
RewriteCond %{QUERY_STRING} (<|%3C)([^s]*s)+cript.*(>|%3E) [NC,OR]
# Block out any script trying to set a PHP GLOBALS variable via URL.
RewriteCond %{QUERY_STRING} GLOBALS(=|\[|\%[0-9A-Z]{0,2}) [OR]
# Block out any script trying to modify a _REQUEST variable via URL.
RewriteCond %{QUERY_STRING} _REQUEST(=|\[|\%[0-9A-Z]{0,2})
# Return 403 Forbidden header and show the content of the root homepage
RewriteRule .* index.php [F]
#
## End - Exploits
## Begin - Index
# If the requested path and file is not /index.php and the request
# has not already been internally rewritten to the index.php script
RewriteCond %{REQUEST_URI} !^/index\.php
# and the requested path and file doesn't directly match a physical file
RewriteCond %{REQUEST_FILENAME} !-f
# and the requested path and file doesn't directly match a physical folder
RewriteCond %{REQUEST_FILENAME} !-d
# internally rewrite the request to the index.php script
RewriteRule .* index.php [L]
## End - Index
## Begin - Security
# Block all direct access for these folders
RewriteRule ^(\.git|src|var|tests)/(.*) error [F]
# Block access to specific file types for these system folders
RewriteRule ^(src|vendor)/(.*)\.(txt|xml|md|html|neon|json|json5|yaml|yml|php|pl|py|cgi|twig|sh|bat|neon|json)$ error [F]
# Block access to specific file types for these project folders
RewriteRule ^(project)/(.*)\.(txt|md|yaml|yml|neon|json|json5|php|pl|py|cgi|twig|html|sh|bat|neon|json)$ error [F]
# Block all direct access to .md files:
RewriteRule \.md$ error [F]
# Block all direct access to files and folders beginning with a dot
RewriteRule (^|/)\.(?!well-known) - [F]
# Block access to specific files in the root folder
RewriteRule ^(phpstan\.neon|phpunit\.xml|BACKERS\.md|CHANGELOG\.md|CONTRIBUTING\.md|README\.md|LICENSE\.txt|composer\.lock|composer\.json|\.htaccess)$ error [F]
## End - Security
## Begin - Rewrite rules for SEO improvements.
# RewriteCond %{HTTP_HOST} ^www.example.org [NC]
# RewriteRule ^(.*)$ http://example.org/$1 [R=301,L]
# Redirect 301 /index http://example.org/
## End - Rewrite rules for SEO improvements.
</IfModule>
## Begin - Prevent Browsing and Set Default Resources
Options -Indexes
DirectoryIndex index.php index.html index.htm
## End - Prevent Browsing and Set Default Resources