Here is a simple cheatsheet for the .htaccess file:
Enable Directory Browsing
Options +Indexes## block a few types of files from showing
IndexIgnore *.wmv *.mp4 *.avi
Disable Directory Browsing
Options All -IndexesCustomize Error Messages
ErrorDocument 403 /forbidden.htmlErrorDocument 404 /notfound.html
ErrorDocument 500 /servererror.html
Get SSI working with HTML/SHTML
AddType text/html .htmlAddType text/html .shtml
AddHandler server-parsed .html
AddHandler server-parsed .shtml
# AddHandler server-parsed .htm
Change Default Page (order is followed!)
DirectoryIndex myhome.htm index.htm index.phpBlock Users from accessing the site
<limit GET POST PUT>order deny,allow
deny from 202.54.122.33
deny from 8.70.44.53
deny from .spammers.com
allow from all
</limit>
Allow only LAN users
order deny,allowdeny from all
allow from 192.168.0.0/24
Redirect Visitors to New Page/Directory
Redirect oldpage.html http://www.domainname.com/newpage.htmlRedirect /olddir http://www.domainname.com/newdir/
Block site from specific referrers
RewriteEngine onRewriteCond %{HTTP_REFERER} site-to-block\.com [NC]
RewriteCond %{HTTP_REFERER} site-to-block-2\.com [NC]
RewriteRule .* - [F]
Block Hot Linking/Bandwidth hogging
RewriteEngine onRewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^http://(www\.)?mydomain.com/.*$ [NC]
RewriteRule \.(gif|jpg)$ - [F]
Want to show a "Stealing is Bad" message too?
Add this below the Hot Link Blocking code:
RewriteRule \.(gif|jpg)$ http://www.mydomain.com/dontsteal.gif [R,L]Stop .htaccess (or any other file) from being viewed
<files file-name>order allow,deny
deny from all
</files>
Avoid the 500 Error
# Avoid 500 error by passing charsetAddDefaultCharset utf-8
Grant CGI Access in a directory
Options +ExecCGIAddHandler cgi-script cgi pl
# To enable all scripts in a directory use the following
# SetHandler cgi-script
Password Protecting Directories
Use the .htaccess Password Generator and follow the brief instructions!
Change Script Extensions
AddType application/x-httpd-php .gnegne will now be treated as PHP files! Similarly, x-httpd-cgi for CGI files, etc.
Use MD5 Digests
Performance may take a hit but if thats not a problem, this is a nice option to turn on.
ContentDigest OnThe CheckSpelling Directive
From Jens Meiert: CheckSpelling corrects simple spelling errors (for example, if someone forgets a letter or if any character is just wrong). Just add CheckSpelling On to your htaccess file.
The ContentDigest Directive
As the Apache core features documentation says: "This directive enables the generation of Content-MD5 headers as defined in RFC1864 respectively RFC2068. The Content-MD5 header provides an end-to-end message integrity check (MIC) of the entity-body. A proxy or client may check this header for detecting accidental modification of the entity-body in transit.
Note that this can cause performance problems on your server since the message digest is computed on every request (the values are not cached). Content-MD5 is only sent for documents served by the core, and not by any module. For example, SSI documents, output from CGI scripts, and byte range responses do not have this header."
To turn this on, just add ContentDigest On.
Save Bandwidth
# Only if you use PHP<ifmodule mod_php4.c>
php_value zlib.output_compression 16386
</ifmodule>
Resources...
- The Jackol's Den
- Web Master known as The Jackol.. Great information, tutorials, tips, tricks, and various resources.
Worthy Reads On Amazon...
The Zen of CSS Design: Visual Enlightenment for the Web (Voices That Matter)
Amazon Price: $29.69 (as of 10/11/2008)
Bulletproof Web Design: Improving flexibility and protecting against worst-case scenarios with XHTML and CSS
Amazon Price: (as of 10/11/2008)
Reader Feedback
Like this lens? Want to share your feedback, or just give a thumbs up? Be the first to submit a blurb!
