Comment on Using SVN makes your site extremely vulnerableComments−ionfish16yFor your Apache config. # Disallow viewing of .svn and .git directory contents <DirectoryMatch \.(svn|git)> Order allow,deny Deny from all </DirectoryMatch>−bcl16yMay as well throw in .hgOh. Now we're blacklisting.If you are going to use this solution, you are better off blacklisting all dotfiles except .htaccess, assuming you allow it.−ionfish16yEven if you do use .htaccess files, you still shouldn't be showing them to anyone who requests them from your web server!−bcl16yHa! Correct!−patio1116yFor Nginx:location ~ /\.(svn|git) { deny all; }−djdarkbeat16y # Disallow viewing of .svn and .git and .hg directory contents <Directory ~ \.(svn|git|hg)> Order allow,deny Deny from all </Directory>−djdarkbeat16yAs well as leaving .gitignore exposed also.
Comments
For your Apache config.
May as well throw in .hg
Oh. Now we're blacklisting.
If you are going to use this solution, you are better off blacklisting all dotfiles except .htaccess, assuming you allow it.
Even if you do use .htaccess files, you still shouldn't be showing them to anyone who requests them from your web server!
Ha! Correct!
For Nginx:
location ~ /\.(svn|git) { deny all; }
As well as leaving .gitignore exposed also.