Emediate Posted April 22, 2022 Posted April 22, 2022 A member pointed this out to me this morning and it's not something I had come across or considered before. Our /forums/uploads directory is browsable - along with the corresponding monthly subdirectories which are created by IPS. I wouldn't have thought it an issue, until the same member suggested that some of these images often contain sensitive information such as bank transfer details or account information. Is this a bug, or expected functionality?
teraßyte Posted April 22, 2022 Posted April 22, 2022 Usually an empty index.html file is created inside those folder so that nobody can browse them for files. Also, you should be able to block this at the server level. It depends on your hosting/server config/etc though.
Solution Marc Posted April 22, 2022 Solution Posted April 22, 2022 As mentioned, there should be an index.html file in each, that would stop them being browsable. Please check that first of all. If there is one present and you are still able to browse the folder, you need to contact your hosting company as they are not processing index.html as a default page for directories
Emediate Posted April 22, 2022 Author Posted April 22, 2022 Thanks all. I know where to look now 🙂 Cheers. Marc 1
Recommended Posts