Protecting access to web directories with htaccess



Okay, in an earlier article I was looking at uses of Google that might reveal things you don’t want revealed about your website. Maybe a test directory that you don’t want to be spidered. I want to say that it’s not possible to keep it hidden just by NOT linking to it. That’s what some will suggest, the argument goes along these lines “spiders just follow links, so don’t link to a directory or document you don’t want the web spiders to see.” Spidering bots seem to be a bit more resourceful though, I’ve seen files and folders that I can’t imagine were linked to being picked up in a web search, so how do we prevent that?

For that matter what about the people that might get lucky and guess our testing directory? There’s one answer that can solve both of these problems. It’s done using the .htaccess file.

You’re going to probably need to log into the command shell on your webserver unless your host has a control panel to deal with this. Password protect directories is what we’re going to do.

You need to create a file in the directory that you want to protect, let’s say it’s yourdomain.com/test and the path is /var/www/html/test
AuthUserFile /var/www/html/test/.htpasswd
AuthName protectedtest
AuthType Basic

require valid-user

Ok, this is good save and close, make sure that it is called .htaccess (a period in front of htaccess)

Then make sure you’re in the directory to be protected…

type the following to create the .htpasswd file and setup the first user

htpasswd -c .htpasswd testfolderuser

future users can be added by the following

htpasswd .htpasswd secondtestuser

After each of the above commands you will be prompted for a password for the user and then prompted to confirm it and everything should be set. There are some warnings to go along with this. Don’t put your .htpasswd file in a folder that can be viewed without permission. It’s USUALLY advisable to put it outside of the web-tree somewhere. If you do that, make sure to 1) specify the absolute path in the .htaccess file so .htaccess can find your password list. and 2) when running htpasswd, make sure to specify the absolute path to the .htpasswd file you are changing.

It is possible to have multiple password protected directories using either the same file of usernames and passwords, or a different set of usernames and passwords by using a different filename.

Related Posts

Blog Traffic Exchange Related Posts
  • Emailing large files.... There are lot's of ways to get a file from one place to another, emailing is the first that many think of. (For larger files I'll usually just upload to a directory on the website and then email a link...) The problem with email is multiple.... 1)viruses exploit email as......
  • Open Source Web templates One of the things that I've really not looked at until lately is the use of open source web templates. I don't know why but I've never really paid much attention to the thought of templates outside of those for a cms platform like wordpress or ezcontents, etc. However, recently......
  • bbpress mod_rewrite Woes I don't know if you're familiar with bbpress, it's the forum cousin of wordpress and can integrate nicely into the wordpress database to allow users to be shared across the two installs. So, on my North Carolina Genealogy site and my South Carolina Genealogy site I have bbpress forums installed.......
Blog Traffic Exchange Related Websites
  • Twenty Steps To Getting Your Blog Setup For Quick Traffic With blogs showing up every seconds, it’s a complete mystery to many bloggers how to build their blog site to stand out from the crowd. It’s simple really. People prefer to read good content that is instantly actionable. These actionable tips should certainly benefit your blog site making it feel......
  • Useful Applications on the Go If you're a geek like me and you carry around a USB drive on your keychain, you might be looking for some useful utilities to keep on your drive.  First and foremost you need to protect your portable drive with encryption.  Information can fall into the wrong hands if the......
  • Templates For E-Commerce Web Hosting Developing a expert website may be difficult. E-commerce internet style is truly a complex animal. To cut development time, numerous web hosting organizations start offering web hosting templates or hosting with templates. Whether or not you are looking for a easy internet website or a functional e-commerce website, the chances......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site