modify .htaccess with extra safety after malicious code - Forum | JoomShaper
Staff replied General

modify .htaccess with extra safety after malicious code

Asked by Seppe 3 months ago Last activity 3 months ago

In the main threat, I saw a couple of answers with people offering extra code to add to the .htaccess in the root folder.
When I add it, my front- and backend of the website give me a "500 internal error code".
Am I missing something?
I tried with 2 different blocks of code:

<IfModule mod_authz_core.c> <FilesMatch ".(php|phtml|php[0-9]|phps)$"> Require all denied </FilesMatch> ></IfModule>
<IfModule !mod_authz_core.c> <FilesMatch ".(php|phtml|php[0-9]|phps)$"> Order allow,deny Deny from all </FilesMatch> </IfModule>

or

<DirectoryMatch "/(media|images|uploads|tmp|cache|administrator/cache|assets|icons|fonts)(/|$)"> AllowOverride None <FilesMatch "(?i).(php|phtml|phar|php[0-9]?|php..*|shtml)$"> Require all denied </FilesMatch> </DirectoryMatch>

5 replies

Pascal - HTProtect.org

The 500 Internal Server Error is expected with those snippets.

The second one cannot be used in a .htaccess file because DirectoryMatch and AllowOverride are only valid in the Apache server or VirtualHost configuration. Apache will therefore return a 500 error.

The first snippet also shouldn't be added to Joomla's root .htaccess, as it would block the execution of all PHP files, including index.php, effectively breaking both the frontend and backend.

If your goal is to prevent PHP execution in writable directories (images, media, tmp, cache, etc.), the rules must be applied only to those directories, or configured centrally in the Apache configuration.

For an easier setup, you could use Admin Tools Pro's .htaccess Maker or my free HTProtect extension. Both deploy the appropriate protection rules with just one or two clicks, eliminating the need to edit .htaccess files manually or risk breaking your site.

Seppe Asked this

I tried to install your extension, but I always get a red banner, without any explenation why it won't install....

Seppe Asked this

Debugmode is ON, and error reporting is set to MAX

still no changes.
Only the red block, without any text

Pascal - HTProtect.org
3 months ago · edited

That's definitely not expected. What does the red banner say? Could you please enable Joomla System Debug, try the installation again, and let me know the exact error message?

System → Global Configuration → System → Debug System = Yes

Seppe Asked this

Now I get a "403 error" that I don't have permission to acces this resource...

Pascal - HTProtect.org

It looks like there's a more general issue with your Joomla installation. I've never seen that empty red bar before.

Seppe Asked this

I tried a 3th website.

Its always the same.
at the first try, I get the "403 forbidden" screen: you don't have persmission to access this resource

starting the 2nd attempt, I get this red bar, like in the screenshot.

Seppe Asked this

Even the "https://github.com/zkrana/joomla-security-scanner" says:

Hardening
The most effective server-level fix is blocking PHP execution in directories that should only ever hold static assets. Add this to your site's .htaccess:

<DirectoryMatch "/(media|images|uploads|tmp|cache|assets|icons|fonts)(/|$)">
AllowOverride None
<FilesMatch "(?i).(php|phtml|phar|php[0-9]?|php..*|shtml)$">
Require all denied
</FilesMatch>
</DirectoryMatch>

also this gives me the 500 error code

Seppe Asked this
3 months ago · edited

I will try a different website... and is exactly the same

Pascal - HTProtect.org

If you'd like, I could help you sort that out: Live-Chat
It's already running on a few hundred sites, and I've never encountered an install issue like that before.

Who's your hosting provider? Is this different website hosted on the same webspace?

Ziaul Kabir Staff

Hi Seppe,

The .htaccess snippets shared in the GitHub guide are intended as general server-level hardening recommendations. Depending on your server configuration (Apache version, hosting environment, or whether the directives are allowed in .htaccess), some of these rules may result in a 500 Internal Server Error.

If adding the rules breaks your site, please remove them and restore the original .htaccess.

At this point, we recommend checking with your hosting provider to confirm which Apache directives are supported in your environment before applying additional hardening rules. They can also advise on the correct way to block PHP execution in writable directories for your specific server configuration.

Best regards,

Log in to reply.