View Single Post
  #1   IP: 112.87.30.132
Old 2014-01-07, 07:35 PM
topvip topvip is offline
超级版主
 
Join Date: 2006-01-04
Posts: 1206
topvip 正向着好的方向发展
Default 禁止X3.1的 上传的 附件、图片的目录运行php

新建一个.htaccess文件, 内容如下:
Code:
# deny *everything*
<FilesMatch ".*">
  Order Allow,Deny
  Deny from all
</FilesMatch>

# but now allow just *certain* necessary files:
<FilesMatch ".*\.(jpe?g|JPE?G|gif|GIF|png|PNG|swf|SWF)$" >
  Order Allow,Deny
  Allow from all
</FilesMatch>

IndexIgnore */*


## NOTE: If you want even greater security to prevent hackers from running scripts in this folder, uncomment the following line (if your hosting company will allow you to use OPTIONS):
# OPTIONS -Indexes -ExecCGI
AddHandler cgi-script .php .pl .py .rb .jsp .asp .htm .shtml .sh .cgi
Options -ExecCGI
上传到data/attachment/forum下就可以了.
Reply With Quote