Index: branches/5.1.x/tools/.htaccess =================================================================== diff -u -N --- branches/5.1.x/tools/.htaccess (revision 0) +++ branches/5.1.x/tools/.htaccess (revision 13377) @@ -0,0 +1,4 @@ + + order allow,deny + deny from all + \ No newline at end of file Index: branches/5.1.x/.htaccess =================================================================== diff -u -N --- branches/5.1.x/.htaccess (revision 0) +++ branches/5.1.x/.htaccess (revision 13377) @@ -0,0 +1,57 @@ +### File security +# Exclude direct access to tpl, tpl.xml, inc.php, sql extensions +# + + order allow,deny + deny from all + + +# Exclude direct access + + order allow,deny + deny from all + + +## Enable mod-rewrite +RewriteEngine On + +###### Rewrite rule to force 'www.' prefix. Use only if needed +# If your site can be accessed both with and without the 'www.' prefix, +# use the following setting to redirect all users to access the site with the 'www.' +# when they access without 'www.'. Uncomment and MAKE sure to adapt for your domain name +# +# RewriteCond %{HTTP_HOST} ^example\.com$ [NC] +# RewriteRule ^(.*)$ http://www.example.com/$1 [L,R=301] + +###### Rewrite rules to block common hacks +## If you experience problems comment out the operations listed below +## Block out any script trying to base64_encode crap to send via URL +RewriteCond %{QUERY_STRING} base64_encode.*\(.*\) [OR] +## Block out any script that includes a