Turn Off Directory Browsing to Protect Your Web Content

by Gobala Krishnan on April 3, 2008

In my post about the Top 10 Silly Mistakes, a lot of readers were surprised about one particular seemingly “common” mistake, which is not turning off directory browsing for your folders.

This is really simple to do, and will avoid your web content from being stolen as people will not be able to browse the contents of your folder by typing it into the browser. If you type in www.yoursite.com/wp-content/plugins and directory browsing is not turned off for your web site, you can see the content of the entire folder, like this:

directory-browsing

This exposes your website to thieves and hackers, making their lives much easier and serving your files to them on a silver platter.

To turn off directory browsing, simple log into your Cpanel account and look for the “Index Manager” icon, click on it.

directory-browsing-2

This will take you to another page where you can turn off directory browsing for individual folders, or for the entire site. Usually, to turn off indexing for the entire site you need to click on the root folder, which is public_html

directory-browsing-3

Finally, change the settings from “Default System Setting” to “No Indexing”. Now, your folders should be protected from peeping toms forever.

directory-browsing-4

Running an online business involves learning how to secure your website, intellectual property, and business processes from people that mean to do you harm, and turning off directory browsing is the easiest (but most overlooked) way to get started in the right path.

VN:F [1.3.4_676]
Rating: 0.0/10 (0 votes cast)

No related posts.

{ 38 comments… read them below or add one }

1 Rasel 04.03.08 at 6:40 pm

Really its a very helpful tips. I have seen many people are really not concern about this tricky important fact. Even though they know, they don’t know how to protect. Hope this one will help bloggers to protect their blogs from being hacked.
Anyway, anyone one can also protect directory browsing by just only placing a blank index.php file in every directory where they don’t have any index.php file. But have to be careful in few things. So I also prefer Gobala’s suggestion. Its very straight forward. thanks Gobala.

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
2 DS. GOPHEKAR RAAJ 04.04.08 at 2:30 am

Very useful tips Gobala…I never thought that this could make peeping toms away. Hopefully it will…anyway, I’ve turned the indexing off on my site. Thx for your tips.

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
3 K 04.04.08 at 3:02 pm

Above you stated:

In my post about the Top 10 Silly Mistakes, a lot of readers were surprised about one particular seemingly “common” mistake…

Then I looked on this page because I wanted to find the article on “Top 10 Silly Mistakes.” I found no way to access this or any ARCHIVE listed.

Gabala, how does one find this article or any previous ones you’ve written? Thank you & great article on securing your Directory Browser!

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
4 K 04.04.08 at 3:06 pm

Sorry, forget posting the last comment – I just now saw your ARCHIVE listed at the very top of this pg. :) Just woke up!

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
5 @hmed 04.05.08 at 4:28 pm

Thanks For helpful tip.

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
6 Gobala Krishnan 04.06.08 at 2:49 pm

No problem :)

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
7 Tom Lindstrom 04.07.08 at 7:50 pm

Thanks for the tips Gobala! I never thought of that one before.We need to protect our web content at all cost.

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
8 Rick Cowles 04.12.08 at 1:49 am

Great tips, I never thought of this before, really help in protecting my websites. I wonder what other security measures I might have overlooked.
Thanks Gobala.

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
9 azrinbme 04.13.08 at 4:20 pm

Hi Gobala. Thanks for your tips. Myself new bie in blog your advice really helpful especially like me using personal hosting

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
10 Galadriel 04.16.08 at 4:41 am

Dear Gobala,

Thank you so much for this. :)

Usually I upload a blank .html file in every folder but this will save me a lot of effort.

Hoping to meet up with you at JomSeminar and any other times.

See you, my friend.

Galadriel.

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
11 Alex Newell 04.16.08 at 9:17 am

O Golly, I even read the previous article and did not notice this problem. I’m glad I came back to your blog!
:-)

Alex

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
12 Dim from Free Online Poker Tips 04.17.08 at 11:32 am

Gobala, this is a perfect and very useful tip. I will spread this post on the forums because this is a must to know for every blogger.

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
13 eLifestyler 04.19.08 at 3:29 pm

Great article! Thank you very much for sharing this valuable tip with everyone! Definately will come back for more:)

Regards,
Kate

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
14 Fernanda Estrada 04.20.08 at 8:30 am

Thank you very much Gobala

This is a great tip on security and will save me a lot of work.

Fernanda Estrada

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
15 Robert Redl 04.20.08 at 7:42 pm

I want to add that if you use the Apache Webserver,
there exists a very old bug, but it can still be found on many servers out there.

Even if Directory browsing is disabled and

somedomain.com/someurl/

would deliver the index.html page,

adding a second slash would show the directory to you

somedomain.com/someurl//

Try it our, and if it applies to your Webserver do the upgrade.

Also look into the term “Google Hacking” where you see that the Google Search Engine can exploit private information if your webserver is not patched to the latest version.

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
16 Calvin 04.24.08 at 10:27 pm

off topic, what is ‘Unique Article Automator’? if the screen shot is yours, it sounds like ur into splog, spamming the blog with spammy articles… which I doubt it is true. What is it? What is ‘Unique Article Automator’

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
17 Gobala Krishnan 04.28.08 at 6:01 am

You’re obviously not ready for the answer. So I won’t give it :)

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
18 tm 05.01.08 at 5:50 am

Yes I do that but I also have a autoban script located as index.php in my main images directory that blocks any user from all my site if he tries that.

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
19 Calvin 05.01.08 at 3:16 pm

I googled for the plugin and found the answer, if that is the key to success then I know what I should do. :) anyway, respect goes to you for not filtering the comments.

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
20 iCalvyn 05.03.08 at 8:17 am

Great tips, My self did not realize the method to protect the file, i always wonder why some people website have the list, and some did not…

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
21 Sag bohara 05.12.08 at 1:39 pm

This is really good information, i usually do.. peeping like that way to check which competitors using which plugin :D :evil: and never find out the solution for that.. infact never tried out to find out but now, seem like i got it good information .. :) doing stumble and yes advance congrats and best wishes for your new marriage life :)

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
22 Stephanie 05.13.08 at 5:57 am

Thank you!! I never knew I needed to do this before.

stephanie

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
23 nasrun 06.02.08 at 3:08 pm

Thank you..

This information is vwry useful..

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
24 Izzportal 06.04.08 at 3:26 am

Thank you for the tips.It’s helpful.

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
25 Pangeran 06.04.08 at 8:26 am

Thank you for this topic.
I never know how to protect my directory before…
But I know this trick(See the directory)…

But, how about the SEO?
Does “no-index” bring something that “no-index” for spiders and bots too?

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
26 titan 06.04.08 at 1:12 pm

i already know about that and fixed after i know my mistake. Its good guidelines and thanks for telling us about that.

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
27 revenue 06.06.08 at 6:08 pm

Wow thanks god i found this post , now i will turn of all my sites index, i hope u can post other usefull tricks about website security

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
28 Arifin 06.12.08 at 12:43 am

you really good person i ever known…thank u very much for this task, its all really helpfull for protected against hacker, but it’s still many ways to get it. i really appreciate for this your article, i love it

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
29 Kamal Talib 06.26.08 at 4:17 am

Thanks for the tutorial on disabling viewing for web directories.
I already disable my indexes in my control panel.

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
30 Mira 06.29.08 at 9:10 am

Thanks for the really helpful tips Gobala…
It prevents our sites…

Again, appreciate your tips

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
31 yasmine 07.02.08 at 3:11 am

Totally awesome…
Great and really helpful tips

WAS also great material
One of my best investment…

You are my fave WP guru :)

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
32 ken 03.10.09 at 2:13 am

Hi, thanks for this tutorial, but I see your own directory browsing still turn on :)

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
33 Gobala Krishnan 03.10.09 at 6:59 am

Is it? I didnt see any?

VN:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
34 Gloson 05.11.09 at 10:02 am

Yes, I can also see your directory index – http://gobalakrishnan.com/wp-content/themes/

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
35 marine biology 05.11.09 at 4:25 pm

Does this have any effect on search engines for SEO stuff? This does not tell search engines not to spider the page right?

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
36 Gobala Krishnan 05.12.09 at 5:48 pm

nope it does not have any effect on search engines :)

VN:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
37 Gobala Krishnan 05.12.09 at 5:50 pm

i fixed that, thanks Gloson

VN:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)
38 harith 06.20.09 at 11:10 pm

Thanks gobala..
i don’t know about that before..
Your tips really help me to protect my web content

VA:F [1.3.4_676]
Rating: 0.0/5 (0 votes cast)

Leave a Comment

You can use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>


Previous post: How Safe Is Your Maybank / Maybank2u Personal Information?

Next post: Create an Awesome PopUp For Your Website