Options -Indexes -ExecCGI
Header set X-Content-Type-Options: "nosniff"
Header set X-Frame-Options: "deny"
FileETag None
Header set X-XSS-Protection "1; mode=block"
Header set Strict-Transport-Security: "max-age=31536000"
Header set Referrer-Policy: "strict-origin-when-cross-origin"
Header set Permissions-Policy: "accelerometer=(), ambient-light-sensor(), autoplay=(), camera=(), display-capture(), encrypted-media=(), fullscreen=(self), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), usb=()"
<FilesMatch "\.(htaccess|gitignore|ini|sh|phps|fla|sql(ite)?|conf|log|ai|psd|js[fp]|mdb|tar|tgz|rar|7z|zsh.*|bash.*|r[bu]|coffee|lock|aspx?|yml|env|wadl|axd|s3cfg|viminfo|history)$">
Require all denied
</FilesMatch>
<LocationMatch "^/(wordpress|wp|trace|old|test|bitrix|backup|db|predb|database|dump|java|soap|sites|lib|html|admin|resources|assets|thirdparty|js|plugin|inc|web|bundle|xmlrpc|manual|cms|media|shop|modules|ycadmin|config|(e)?bak|null|plus|fckeditor|diguo|beifen|shujuku|wls-wsat|utility|dgbf|pma|phpmyadmin|temp|tmp|backs|tp5|mysql|misc|images|vendor|server|cgi|owa|package|node|server).*">
Require all denied
</LocationMatch>
<DirectoryMatch "^/.*/\.git/">
Require all denied
</DirectoryMatch>
SetEnvIfNoCase User-Agent "Screaming Frog" block
SetEnvIfNoCase User-Agent "masscan" block
SetEnvIfNoCase User-Agent "botnet" block
SetEnvIfNoCase User-Agent "zgrab" block
SetEnvIfNoCase User-Agent "Scrapy" block
SetEnvIfNoCase User-Agent "HTTrack" block
SetEnvIfNoCase User-Agent "axios" block
SetEnvIfNoCase User-Agent "Mechanize" block
SetEnvIfNoCase User-Agent "Acunetix" block
SetEnvIfNoCase User-Agent "FHscan" block
SetEnvIfNoCase Referer "vulnweb" block
SetEnvIfNoCase Referer "acunetix" block
SetEnvIfNoCase Referer "bxss.me" block
SetEnvIfNoCase Referer "zajm-zalog-krasnodar.ru" block
SetEnvIfNoCase Referer "womantouch.ru" block
SetEnvIfNoCase Request_URI "^/static" dontlog
SetEnvIfNoCase Request_URI "^/cordova.js$" dontlog
Code-Sprache: Apache (apache)