Add in some exclusions form some leaky files in the admin

This commit is contained in:
Celly 2017-09-21 17:47:37 -04:00
parent a0bd517380
commit e3e3b4da58
2 changed files with 12 additions and 2 deletions

View File

@ -41,7 +41,7 @@ accesslog.format = "%{%s}t|%V|%r|%s|%b"
index-file.names = ( "index.php", "index.html", "index.lighttpd.html" ) index-file.names = ( "index.php", "index.html", "index.lighttpd.html" )
url.access-deny = ( "~", ".inc" ) url.access-deny = ( "~", ".inc", ".md", ".yml", ".ini" )
static-file.exclude-extensions = ( ".php", ".pl", ".fcgi" ) static-file.exclude-extensions = ( ".php", ".pl", ".fcgi" )
compress.cache-dir = "/var/cache/lighttpd/compress/" compress.cache-dir = "/var/cache/lighttpd/compress/"
@ -66,5 +66,10 @@ $HTTP["url"] =~ "^/admin/" {
} }
} }
# Block the github files from being accessible.
$HTTP["url"] =~ "^/admin/(.git|.gitignore|.github)" {
url.access-deny = ("")
}
# Add user chosen options held in external file # Add user chosen options held in external file
include_shell "cat external.conf 2>/dev/null" include_shell "cat external.conf 2>/dev/null"

View File

@ -42,7 +42,7 @@ accesslog.format = "%{%s}t|%V|%r|%s|%b"
index-file.names = ( "index.php", "index.html", "index.lighttpd.html" ) index-file.names = ( "index.php", "index.html", "index.lighttpd.html" )
url.access-deny = ( "~", ".inc" ) url.access-deny = ( "~", ".inc", ".md", ".yml", ".ini" )
static-file.exclude-extensions = ( ".php", ".pl", ".fcgi" ) static-file.exclude-extensions = ( ".php", ".pl", ".fcgi" )
compress.cache-dir = "/var/cache/lighttpd/compress/" compress.cache-dir = "/var/cache/lighttpd/compress/"
@ -85,5 +85,10 @@ $HTTP["url"] =~ "^/admin/" {
} }
} }
# Block the github files from being accessible.
$HTTP["url"] =~ "^/admin/(.git|.gitignore|.github)" {
url.access-deny = ("")
}
# Add user chosen options held in external file # Add user chosen options held in external file
include_shell "cat external.conf 2>/dev/null" include_shell "cat external.conf 2>/dev/null"