/home/techb158/workloadmatch.com/workloadmatch.com
NameSizeModeActions
.well-known/-0755rm
api/-0755rm
assets/-0755rm
BackUp/-0755rm
bootstrap/-0755rm
bower_components/-0755rm
cgi-bin/-0755rm
dist/-0755rm
img/-0755rm
includes/-0755rm
js/-0755rm
layout/-0755rm
Manager/-0755rm
New Load Match/-0755rm
plugins/-0755rm
styles/-0755rm
Teacher/-0755rm
vendor/-0755rm
.htaccess85040644editdlrm
.htaccess-bak85040644editdlrm
.user.ini5880644editdlrm
admin.php331100644editdlrm
authorized.php22240644editdlrm
auto_email_notification.php50030644editdlrm
error.php4510644editdlrm
error_log247637130644editdlrm
footer.php1840644editdlrm
forgetpassword.php35090644editdlrm
form-newsletter.php6580644editdlrm
form-process.php30870644editdlrm
getlang.php2830644editdlrm
home.php167780644editdlrm
index.php191030644editdlrm
myaccounts.php33190644editdlrm
php.ini6370644editdlrm
postPersons.php17570644editdlrm
reset.php35910644editdlrm
Signup.php220160644editdlrm
workloadmatch-deployment.zip316173000644editdlrm
workloadmatch.com.zip326943790644editdlrm
Edit: /home/techb158/workloadmatch.com/workloadmatch.com/.htaccess (8504B)
#Disable dirctory indexes. the line below will hide folders and their contents on any apache server. Use 'Options +Indexes' to unhide Options -Indexes #the line below will hide folders and their contents on goDaddy. Use 'Options +MultiViews' to unhide Options -MultiViews ########################## Block Spam ####################### # drop Range header when more than 2 ranges. # CVE-2011-3192 SetEnvIf Range (,.*?){2,} bad-range=1 RequestHeader unset Range env=bad-range # optional logging. #CustomLog insert-path-and-name-of-log common env=bad-range # Don't allow any pages to be framed - Defends against CSRF Header set X-Frame-Options DENY # prevent mime based attacks Header set X-Content-Type-Options "nosniff" # Only allow JavaScript from the same domain to be run. # Don't allow inline JavaScript to run. Header set X-Content-Security-Policy "allow 'self';" # Turn on IE8-IE9 XSS prevention tools Header set X-XSS-Protection "1; mode=block" ################################################################# # Enable rewrite engine RewriteEngine On # Block suspicious request methods RewriteCond %{REQUEST_METHOD} ^(HEAD|TRACE|DELETE|TRACK|DEBUG) [NC] RewriteRule ^(.*)$ - [F,L] # Block WP timthumb hack RewriteCond %{REQUEST_URI} (timthumb\.php|phpthumb\.php|thumb\.php|thumbs\.php) [NC] RewriteRule . - [S=1] # Block suspicious user agents and requests RewriteCond %{HTTP_USER_AGENT} (libwww-perl|wget|python|nikto|curl|scan|java|winhttp|clshttp|loader) [NC,OR] RewriteCond %{HTTP_USER_AGENT} (<|>|'|%0A|%0D|%27|%3C|%3E|%00) [NC,OR] RewriteCond %{HTTP_USER_AGENT} (;|<|>|'|"|\)|\(|%0A|%0D|%22|%27|%28|%3C|%3E|%00).*(libwww-perl|wget|python|nikto|curl|scan|java|winhttp|HTTrack|clshttp|archiver|loader|email|harvest|extract|grab|miner) [NC,OR] RewriteCond %{THE_REQUEST} \?\ HTTP/ [NC,OR] RewriteCond %{THE_REQUEST} \/\*\ HTTP/ [NC,OR] RewriteCond %{THE_REQUEST} etc/passwd [NC,OR] RewriteCond %{THE_REQUEST} cgi-bin [NC,OR] RewriteCond %{THE_REQUEST} (%0A|%0D) [NC,OR] # Block MySQL injections, RFI, base64, etc. RewriteCond %{QUERY_STRING} [a-zA-Z0-9_]=http:// [OR] RewriteCond %{QUERY_STRING} [a-zA-Z0-9_]=http%3A%2F%2F [OR] RewriteCond %{QUERY_STRING} [a-zA-Z0-9_]=(\.\.//?)+ [OR] RewriteCond %{QUERY_STRING} [a-zA-Z0-9_]=/([a-z0-9_.]//?)+ [NC,OR] RewriteCond %{QUERY_STRING} \=PHP[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12} [NC,OR] RewriteCond %{QUERY_STRING} (\.\./|\.\.) [OR] RewriteCond %{QUERY_STRING} ftp\: [NC,OR] RewriteCond %{QUERY_STRING} http\: [NC,OR] RewriteCond %{QUERY_STRING} https\: [NC,OR] RewriteCond %{QUERY_STRING} \=\|w\| [NC,OR] RewriteCond %{QUERY_STRING} ^(.*)/self/(.*)$ [NC,OR] RewriteCond %{QUERY_STRING} ^(.*)cPath=http://(.*)$ [NC,OR] RewriteCond %{QUERY_STRING} (\<|%3C).*script.*(\>|%3E) [NC,OR] RewriteCond %{QUERY_STRING} (<|%3C)([^s]*s)+cript.*(>|%3E) [NC,OR] RewriteCond %{QUERY_STRING} (\<|%3C).*iframe.*(\>|%3E) [NC,OR] RewriteCond %{QUERY_STRING} (<|%3C)([^i]*i)+frame.*(>|%3E) [NC,OR] RewriteCond %{QUERY_STRING} base64_encode.*\(.*\) [NC,OR] RewriteCond %{QUERY_STRING} base64_(en|de)code[^(]*\([^)]*\) [NC,OR] RewriteCond %{QUERY_STRING} GLOBALS(=|\[|\%[0-9A-Z]{0,2}) [OR] RewriteCond %{QUERY_STRING} _REQUEST(=|\[|\%[0-9A-Z]{0,2}) [OR] RewriteCond %{QUERY_STRING} ^.*(\[|\]|\(|\)|<|>).* [NC,OR] RewriteCond %{QUERY_STRING} (NULL|OUTFILE|LOAD_FILE) [OR] RewriteCond %{QUERY_STRING} (\./|\../|\.../)+(motd|etc|bin) [NC,OR] RewriteCond %{QUERY_STRING} (localhost|loopback|127\.0\.0\.1) [NC,OR] RewriteCond %{QUERY_STRING} (<|>|'|%0A|%0D|%27|%3C|%3E|%00) [NC,OR] RewriteCond %{QUERY_STRING} concat[^\(]*\( [NC,OR] RewriteCond %{QUERY_STRING} union([^s]*s)+elect [NC,OR] RewriteCond %{QUERY_STRING} union([^a]*a)+ll([^s]*s)+elect [NC,OR] RewriteCond %{QUERY_STRING} (;|<|>|'|"|\)|%0A|%0D|%22|%27|%3C|%3E|%00).*(/\*|union|select|insert|drop|delete|update|cast|create|char|convert|alter|declare|order|script|set|md5|benchmark|encode) [NC,OR] # PHP-CGI Vulnerability RewriteCond %{QUERY_STRING} ^(%2d|\-)[^=]+$ [NC,OR] #proc/self/environ? no way! RewriteCond %{QUERY_STRING} proc\/self\/environ [NC,OR] RewriteCond %{QUERY_STRING} (sp_executesql) [NC] RewriteRule ^(.*)$ - [F,L] ################################################################# # Block Russian Referrer Spam RewriteEngine on RewriteCond %{HTTP_REFERER} ^http://.*ilovevitaly\.com/ [NC,OR] RewriteCond %{HTTP_REFERER} ^http://.*ilovevitaly.\.ru/ [NC,OR] RewriteCond %{HTTP_REFERER} ^http://.*ilovevitaly\.org/ [NC,OR] RewriteCond %{HTTP_REFERER} ^http://.*ilovevitaly\.info/ [NC,OR] RewriteCond %{HTTP_REFERER} ^http://.*iloveitaly\.ru/ [NC,OR] RewriteCond %{HTTP_REFERER} ^http://.*econom\.co/ [NC,OR] RewriteCond %{HTTP_REFERER} ^http://.*savetubevideo\.com/ [NC,OR] RewriteCond %{HTTP_REFERER} ^http://.*kambasoft\.com/ [NC,OR] RewriteCond %{HTTP_REFERER} ^http://.*buttons\-for\-website\.com/ [NC,OR] RewriteCond %{HTTP_REFERER} ^http://.*semalt\.com/ [NC,OR] RewriteCond %{HTTP_REFERER} ^http://.*darodar\.com/ [NC] RewriteCond %{HTTP_REFERER} ^http://.*seoanalyses\.com/ [NC] RewriteRule ^(.*)$ – [F,L] ##Method #1: Block the Referrer Used by Spam Bots RewriteEngine On Options +FollowSymlinks RewriteCond %{HTTP_REFERER} ^https?://([^.]+\.)*blackhatworth\.com\ [NC,OR] RewriteRule .* – [F] ##Method #2: Block the Referrer Used by Spam Bots RewriteEngine On Options +FollowSymlinks RewriteCond %{HTTP_USER_AGENT} Baiduspider [NC] RewriteRule .* – [F,L] ########################## Block Spam ####################### ####################ErrorDocument########################## ErrorDocument 404 https://workloadmatch.com/404.php FallbackResource /404.php ############# Hide .PHP ##################### # Enable URL rewriting RewriteEngine on # Remove .php extension from URLs RewriteCond %{THE_REQUEST} /([^.]+)\.php [NC] RewriteRule ^ /%1 [NC,L,R] # Add .php extension internally RewriteCond %{REQUEST_FILENAME}.php -f RewriteRule ^ %{REQUEST_URI}.php [NC,L] # Redirect non-www to www and force HTTPS RewriteCond %{HTTP_HOST} ^techbala\.ca [NC,OR] RewriteCond %{HTTPS} off RewriteRule ^ https://www.workloadmatch.com%{REQUEST_URI} [R=301,L] ## Redirect /Teacher_ID/ URLs #RewriteCond %{THE_REQUEST} ^[A-Z]{3,}\s/+Teacher_ID/([^\s]+) [NC] #RewriteRule ^ /Teacher_ID/%1 [R=301,L] # ## Internal rewrite for /Teacher_ID/ URLs #RewriteCond %{REQUEST_FILENAME} !-d #RewriteCond %{DOCUMENT_ROOT}/Teacher_ID/$1.php -f #RewriteRule ^(.+?)/?$ /Teacher_ID/$1.php [L] # Set alternate default index page DirectoryIndex home.php # Redirect non-existing pages to index.php Options +SymLinksIfOwnerMatch RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule ^ index.php [L] #RewriteEngine On #Options +FollowSymlinks #RewriteCond %{REQUEST_FILENAME} !-f #RewriteCond %{REQUEST_FILENAME} !-d #RewriteRule ^(.*)$ index.php [NC,QSA] # BEGIN cPanel-generated php ini directives, do not edit # Manual editing of this file may result in unexpected behavior. # To make changes to this file, use the cPanel MultiPHP INI Editor (Home >> Software >> MultiPHP INI Editor) # For more information, read our documentation (https://go.cpanel.net/EA4ModifyINI) php_flag display_errors Off php_value max_execution_time 30 php_value max_input_time 60 php_value max_input_vars 1000 php_value memory_limit 256M php_value post_max_size 256M php_value session.gc_maxlifetime 1440 php_value session.save_path "/var/cpanel/php/sessions/ea-php74" php_value upload_max_filesize 256M php_flag zlib.output_compression Off php_flag display_errors Off php_value max_execution_time 30 php_value max_input_time 60 php_value max_input_vars 1000 php_value memory_limit 256M php_value post_max_size 256M php_value session.gc_maxlifetime 1440 php_value session.save_path "/var/cpanel/php/sessions/ea-php74" php_value upload_max_filesize 256M php_flag zlib.output_compression Off # END cPanel-generated php ini directives, do not edit # #order allow,deny #allow from all # #deny from all # allow from 70.81.225.75 # allow from 74.57.59.69 # # #deny from 58.220.27.151 # php -- BEGIN cPanel-generated handler, do not edit # Set the “ea-php74” package as the default “PHP” programming language. AddHandler application/x-httpd-ea-php74 .php .php7 .phtml # php -- END cPanel-generated handler, do not edit