Discussion:
Bug#913038: disable indexes for /var/www/
Matus UHLAR - fantomas
2018-11-06 09:56:01 UTC
Permalink
Package: apache2
Version: 2.4.10-10+deb8u12

Hello,

the default apache2.conf contains:

<Directory /var/www/>
Options Indexes FollowSymLinks
AllowOverride None
Require all granted
</Directory>

Please don't enable Indexes by default for /var/www and subdirectories.

Let users allow it when they need it, but don't allow directory listings
unless they do so.

Some people treat directory listings like security hole. I believe the
default should be the safer option - indexes disabled.
--
Matus UHLAR - fantomas, ***@fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
The early bird may get the worm, but the second mouse gets the cheese.
Loading...