Jump to content

Should the Uploads directories be browsable?


Go to solution Solved by Marc,

Recommended Posts

Posted

A member pointed this out to me this morning and it's not something I had come across or considered before.

Our /forums/uploads directory is browsable - along with the corresponding monthly subdirectories which are created by IPS.

I wouldn't have thought it an issue, until the same member suggested that some of these images often contain sensitive information such as bank transfer details or account information.

Is this a bug, or expected functionality?

Posted

Usually an empty index.html file is created inside those folder so that nobody can browse them for files.

Also, you should be able to block this at the server level. It depends on your hosting/server config/etc though.

  • Solution
Posted

As mentioned, there should be an index.html file in each, that would stop them being browsable. Please check that first of all. If there is one present and you are still able to browse the folder, you need to contact your hosting company as they are not processing index.html as a default page for directories

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...