Skip to content

Instantly share code, notes, and snippets.

@aboritskiy
Created October 12, 2018 20:50
Show Gist options
  • Save aboritskiy/cf2a629af830cb350e7fb9a29e0773df to your computer and use it in GitHub Desktop.
Save aboritskiy/cf2a629af830cb350e7fb9a29e0773df to your computer and use it in GitHub Desktop.
Apache2.4 block Magento1 guts
RewriteRule ^/\. - [L,R=403]
RewriteRule ^/app/ - [L,R=403]
RewriteRule ^/dev/ - [L,R=403]
RewriteRule ^/downloader/ - [L,R=403]
RewriteRule ^/includes/ - [L,R=403]
RewriteRule ^/lib/ - [L,R=403]
RewriteRule ^/shell/ - [L,R=403]
RewriteRule ^/pkginfo/ - [L,R=403]
RewriteRule ^/var/ - [L,R=403]
RewriteRule ^/rss/ - [L,R=403]
RewriteRule ^/docs - [L,R=403]
RewriteRule ^/install\.php - [L,R=403]
RewriteRule ^/cron\.php - [L,R=403]
#mind api.php, block it as well if not used.
<Files api.php>
Require all denied
</Files>
<Files cron.php>
Require all denied
</Files>
<Files cron.sh>
Require all denied
</Files>
<Files get.php>
Require all denied
</Files>
<Files index.php.sample>
Require all denied
</Files>
<Files install.php>
Require all denied
</Files>
<Files LICENSE.html>
Require all denied
</Files>
<Files LICENSE.txt>
Require all denied
</Files>
<Files LICENSE_AFL.txt>
Require all denied
</Files>
<Files mage>
Require all denied
</Files>
<Files n98-magerun.phar>
Require all denied
</Files>
<Files php.ini.sample>
Require all denied
</Files>
<Files RELEASE_NOTES.txt>
Require all denied
</Files>
<Files scheduler_cron.sh>
Require all denied
</Files>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment