3 ms·
location ~ "(^#.*#|~|\.sw[op])$" { return 401; } Or something along those lines. Nodesocket's answer is good as well: http://news.ycombinator.com/
by chrisguitarguy 14y ago
location ~ "(^#.*#|~|\.sw[op])$" {
return 401;
}
Or something along those lines.
Nodesocket's answer is good as well: http://news.ycombinator.com/item?id=5164017 http://news.ycombinator.com/item?id=5164017
- uxp 14y agoIt should be noted that the author states that this htaccess rule "block[s] access to any file containing the string wp-config.php", but the rule itself is designed to block any temporary editor file matching the pattern he describes in the article regardless if it is named wp-config.php or not. Your nginx rule does the same.
- antihero 14y agoNot sure if it's actually that helpful but might be nicer to serve up a 404, in the interest of opacity. Simply giving the hacker less information (though not just depending on this) is a useful form of security. If you give them a 401, then they at least know that the file exists.
- javipas 14y agoThx, I'll try that.