Turn Off Directory Browsing to Protect Your Web Content

In my post about the Top 10 Silly Mistakes, a lot of readers were surprised about one particular seemingly “common” mistake, which is not turning off directory browsing for your folders.

This is really simple to do, and will avoid your web content from being stolen as people will not be able to browse the contents of your folder by typing it into the browser. If you type in www.yoursite.com/wp-content/plugins and directory browsing is not turned off for your web site, you can see the content of the entire folder, like this:

directory-browsing

This exposes your website to thieves and hackers, making their lives much easier and serving your files to them on a silver platter.

To turn off directory browsing, simple log into your Cpanel account and look for the “Index Manager” icon, click on it.

directory-browsing-2

This will take you to another page where you can turn off directory browsing for individual folders, or for the entire site. Usually, to turn off indexing for the entire site you need to click on the root folder, which is public_html

directory-browsing-3

Finally, change the settings from “Default System Setting” to “No Indexing”. Now, your folders should be protected from peeping toms forever.

directory-browsing-4

Running an online business involves learning how to secure your website, intellectual property, and business processes from people that mean to do you harm, and turning off directory browsing is the easiest (but most overlooked) way to get started in the right path.

RSS feed | Trackback URI

31 Comments »

Comment by Rasel
2008-04-03 18:40:21

Really its a very helpful tips. I have seen many people are really not concern about this tricky important fact. Even though they know, they don’t know how to protect. Hope this one will help bloggers to protect their blogs from being hacked.
Anyway, anyone one can also protect directory browsing by just only placing a blank index.php file in every directory where they don’t have any index.php file. But have to be careful in few things. So I also prefer Gobala’s suggestion. Its very straight forward. thanks Gobala.

 
Comment by DS. GOPHEKAR RAAJ
2008-04-04 02:30:22

Very useful tips Gobala…I never thought that this could make peeping toms away. Hopefully it will…anyway, I’ve turned the indexing off on my site. Thx for your tips.

 
Comment by K
2008-04-04 15:02:35

Above you stated:

In my post about the Top 10 Silly Mistakes, a lot of readers were surprised about one particular seemingly “common” mistake…

Then I looked on this page because I wanted to find the article on “Top 10 Silly Mistakes.” I found no way to access this or any ARCHIVE listed.

Gabala, how does one find this article or any previous ones you’ve written? Thank you & great article on securing your Directory Browser!

 
Comment by K
2008-04-04 15:06:11

Sorry, forget posting the last comment - I just now saw your ARCHIVE listed at the very top of this pg. :) Just woke up!

Comment by Gobala Krishnan
2008-04-06 14:49:59

No problem :)

 
 
Comment by @hmed
2008-04-05 16:28:42

Thanks For helpful tip.

 
Comment by Tom Lindstrom
2008-04-07 19:50:24

Thanks for the tips Gobala! I never thought of that one before.We need to protect our web content at all cost.

 
Comment by Rick Cowles
2008-04-12 01:49:47

Great tips, I never thought of this before, really help in protecting my websites. I wonder what other security measures I might have overlooked.
Thanks Gobala.

 
Comment by azrinbme
2008-04-13 16:20:47

Hi Gobala. Thanks for your tips. Myself new bie in blog your advice really helpful especially like me using personal hosting

 
Comment by Galadriel
2008-04-16 04:41:02

Dear Gobala,

Thank you so much for this. :)

Usually I upload a blank .html file in every folder but this will save me a lot of effort.

Hoping to meet up with you at JomSeminar and any other times.

See you, my friend.

Galadriel.

 
Comment by Alex Newell
2008-04-16 09:17:18

O Golly, I even read the previous article and did not notice this problem. I’m glad I came back to your blog!

:-)

Alex

 
2008-04-17 11:32:43

Gobala, this is a perfect and very useful tip. I will spread this post on the forums because this is a must to know for every blogger.

 
Comment by eLifestyler
2008-04-19 15:29:12

Great article! Thank you very much for sharing this valuable tip with everyone! Definately will come back for more:)

Regards,
Kate

 
Comment by Fernanda Estrada
2008-04-20 08:30:10

Thank you very much Gobala

This is a great tip on security and will save me a lot of work.

Fernanda Estrada

 
Comment by Robert Redl Subscribed to comments via email
2008-04-20 19:42:10

I want to add that if you use the Apache Webserver,
there exists a very old bug, but it can still be found on many servers out there.

Even if Directory browsing is disabled and

somedomain.com/someurl/

would deliver the index.html page,

adding a second slash would show the directory to you

somedomain.com/someurl//

Try it our, and if it applies to your Webserver do the upgrade.

Also look into the term “Google Hacking” where you see that the Google Search Engine can exploit private information if your webserver is not patched to the latest version.

 
Comment by Calvin
2008-04-24 22:27:54

off topic, what is ‘Unique Article Automator’? if the screen shot is yours, it sounds like ur into splog, spamming the blog with spammy articles… which I doubt it is true. What is it? What is ‘Unique Article Automator’

Comment by Gobala Krishnan
2008-04-28 06:01:06

You’re obviously not ready for the answer. So I won’t give it :)

Comment by Calvin
2008-05-01 15:16:54

I googled for the plugin and found the answer, if that is the key to success then I know what I should do. :) anyway, respect goes to you for not filtering the comments.

(Comments wont nest below this level)
 
 
 
Comment by tm
2008-05-01 05:50:05

Yes I do that but I also have a autoban script located as index.php in my main images directory that blocks any user from all my site if he tries that.

 
Comment by iCalvyn
2008-05-03 08:17:12

Great tips, My self did not realize the method to protect the file, i always wonder why some people website have the list, and some did not…

 
Comment by Sag bohara
2008-05-12 13:39:50

This is really good information, i usually do.. peeping like that way to check which competitors using which plugin :D :evil: and never find out the solution for that.. infact never tried out to find out but now, seem like i got it good information .. :) doing stumble and yes advance congrats and best wishes for your new marriage life :)

 
Comment by Stephanie
2008-05-13 05:57:12

Thank you!! I never knew I needed to do this before.

stephanie

 
Comment by nasrun
2008-06-02 15:08:10

Thank you..

This information is vwry useful..

 
Comment by Izzportal
2008-06-04 03:26:49

Thank you for the tips.It’s helpful.

 
Comment by Pangeran Subscribed to comments via email
2008-06-04 08:26:27

Thank you for this topic.
I never know how to protect my directory before…
But I know this trick(See the directory)…

But, how about the SEO?
Does “no-index” bring something that “no-index” for spiders and bots too?

 
Comment by titan
2008-06-04 13:12:33

i already know about that and fixed after i know my mistake. Its good guidelines and thanks for telling us about that.

 
Comment by revenue
2008-06-06 18:08:03

Wow thanks god i found this post , now i will turn of all my sites index, i hope u can post other usefull tricks about website security

 
Comment by Arifin
2008-06-12 00:43:52

you really good person i ever known…thank u very much for this task, its all really helpfull for protected against hacker, but it’s still many ways to get it. i really appreciate for this your article, i love it

 
Comment by Kamal Talib
2008-06-26 04:17:46

Thanks for the tutorial on disabling viewing for web directories.
I already disable my indexes in my control panel.

 
Comment by Mira
2008-06-29 09:10:14

Thanks for the really helpful tips Gobala…
It prevents our sites…

Again, appreciate your tips

 
Comment by yasmine
2008-07-02 03:11:28

Totally awesome…
Great and really helpful tips

WAS also great material
One of my best investment…

You are my fave WP guru :)

 
Name (required)
E-mail (required - never shown publicly)
URI
Subscribe to comments via email
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.