|
2013-08-09, 12:13 PM | #1 |
a.k.a. Sparky
Join Date: Sep 2004
Location: West Palm Beach, FL, USA
Posts: 2,396
|
TubeAce exploits
If you are running tubeace, the following rules should be added to your webserver config. Doing it in .htaccess doesn't help as they are able to override that. This assumes Apache 2.x.
Code:
<Directory /var/www/domain.com/avatars/> AllowOverride none RemoveHandler cgi-script .cgi .py .pl <FilesMatch "\.php$"> SetHandler none </FilesMatch> </Directory> <Directory /var/www/domain.com/cache/> AllowOverride none RemoveHandler cgi-script .cgi .py .pl <FilesMatch "\.php$"> SetHandler none </FilesMatch> </Directory> <Directory /var/www/domain.com/thumbs/> AllowOverride none RemoveHandler cgi-script .cgi .py .pl <FilesMatch "\.php$"> SetHandler none </FilesMatch> </Directory> <Directory /var/www/domain.com/uploads/> AllowOverride none RemoveHandler cgi-script .cgi .py .pl <FilesMatch "\.php$"> SetHandler none </FilesMatch> </Directory>
__________________
SnapReplay.com a different way to share photos - iPhone & Android |
|
|