Live data from Hacker News

A collection of useful .htaccess snippets

github.com

11–20 of 22 posts

Re: A collection of useful .htaccess snippets

#13

You can make good http(s) firewalls (albeit not fast as a IP one) against threats. Needs to add more to this, especially configs against SQL injections and other hacks.

Actually, I dont' think that is the webserver's job. Relying on your webserver to protect you against SQL injection is probably not what you want to do. The webserver has no knowledge at all about what kind of program you run behind it. You would need to teach it everything about what you're doing. Seriously, you are much better off just using prepared statements everywhere than trying to teach a webserver the finer…

That's true, but sometimes (especially with completely naive or old PHP) 'using prepared statements everywhere' means 'rewriting everything.' In those cases, htaccess might be the only flexible option you have until you can.

Re: A collection of useful .htaccess snippets

#14
post #4

While I think this is a very valuable resource, and patterns are always welcome by me, it should be noted that the Apache docs recommend against using .htaccess files due to the performance penalty. From the docs ( http://httpd.apache.org/docs/current/howto/htaccess.html ): You should avoid using .htaccess files completely if you have access to httpd main server config file. Using .htaccess files slows down your Apac…

For some hosting situations, the only control you would have would be through the .htaccess file.

Re: A collection of useful .htaccess snippets

#15
post #4

While I think this is a very valuable resource, and patterns are always welcome by me, it should be noted that the Apache docs recommend against using .htaccess files due to the performance penalty. From the docs ( http://httpd.apache.org/docs/current/howto/htaccess.html ): You should avoid using .htaccess files completely if you have access to httpd main server config file. Using .htaccess files slows down your Apac…

PSA: Authorization snippets are based on Apache 2.2 config syntax. Care should be taken to review, update and test Authorization config when upgrading to Apache 2.4 (http://httpd.apache.org/docs/2.4/upgrading.html).

Re: A collection of useful .htaccess snippets

#16
post #13

Earlier quoted context omitted.

Actually, I dont' think that is the webserver's job. Relying on your webserver to protect you against SQL injection is probably not what you want to do. The webserver has no knowledge at all about what kind of program you run behind it. You would need to teach it everything about what you're doing. Seriously, you are much better off just using prepared statements everywhere than trying to teach a webserver the finer…

That's true, but sometimes (especially with completely naive or old PHP) 'using prepared statements everywhere' means 'rewriting everything.' In those cases, htaccess might be the only flexible option you have until you can.

Consider ModSecurity with the Core Rule Set (or Trustwave Commercial Rule Set) instead of attempting to repurpose .htaccess files as a substitute WAF.

Re: A collection of useful .htaccess snippets

#17
post #4

While I think this is a very valuable resource, and patterns are always welcome by me, it should be noted that the Apache docs recommend against using .htaccess files due to the performance penalty. From the docs ( http://httpd.apache.org/docs/current/howto/htaccess.html ): You should avoid using .htaccess files completely if you have access to httpd main server config file. Using .htaccess files slows down your Apac…

These snippets should all be fine to go straight into a directory block, so it's still a really good resource,

Are you sure this is true also for the Rewrite Rules?
Post reply on HN