Protected files are not protected by .htaccess
Posted: October 26th, 2011, 12:16 pm
I have a fresh installation of s2Members and I just discovered that I can manually enter the url to the protected files folder where I get listing of all files and I can freely download any of them.
I see there is an .htaccess file inside but much more complex than in the first video tutorial. The deny from all line is only at the end in this context
I throwed inside an empty index.php file to generate a 404 error instead the file listing. However a savy user can reconstruct files urls by watching the filename in the frontend and by knowing the location of protected files folder.
So I suspect that the .htaccess file is not doing the job it is supposed to do. Any idea?
I see there is an .htaccess file inside but much more complex than in the first video tutorial. The deny from all line is only at the end in this context
- Code: Select all
<IfModule !mod_rewrite.c>
deny from all
</IfModule>
I throwed inside an empty index.php file to generate a 404 error instead the file listing. However a savy user can reconstruct files urls by watching the filename in the frontend and by knowing the location of protected files folder.
So I suspect that the .htaccess file is not doing the job it is supposed to do. Any idea?