diff --git a/.htaccess b/.htaccess index 440cabc..43eec23 100644 --- a/.htaccess +++ b/.htaccess @@ -4,7 +4,12 @@ # Protect files and directories from prying eyes. - Order allow,deny + + Require all denied + + + Order allow,deny + # Don't show directory listings for URLs which map to a directory. diff --git a/includes/file.inc b/includes/file.inc index de9d17d..abdd30f 100644 --- a/includes/file.inc +++ b/includes/file.inc @@ -535,7 +535,18 @@ SetHandler Drupal_Security_Do_Not_Remove_See_SA_2006_006 EOF; if ($private) { - $lines = "Deny from all\n\n" . $lines; + $lines = << + Require all denied + + +# Deny all requests from Apache 2.0-2.2. + + Deny from all + +EOF + . $lines; } return $lines;