From 7c6e37bfafc3309cf4309d8cf46215211cab91bf Mon Sep 17 00:00:00 2001 From: Silvio Rhatto Date: Tue, 3 Dec 2013 12:14:44 -0200 Subject: Fix for SA-CORE-2013-003 --- files/htaccess | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 files/htaccess (limited to 'files/htaccess') diff --git a/files/htaccess b/files/htaccess new file mode 100644 index 0000000..d156a1e --- /dev/null +++ b/files/htaccess @@ -0,0 +1,23 @@ +# Turn off all options we don't need. +Options None +Options +FollowSymLinks + +# Set the catch-all handler to prevent scripts from being executed. +SetHandler Drupal_Security_Do_Not_Remove_See_SA_2006_006 + + # Override the handler again if we're run later in the evaluation list. + SetHandler Drupal_Security_Do_Not_Remove_See_SA_2013_003 + + +# If we know how to do it safely, disable the PHP engine entirely. + + php_flag engine off + +# PHP 4, Apache 1. + + php_flag engine off + +# PHP 4, Apache 2. + + php_flag engine off + -- cgit v1.2.3