Administration Apache Security Tips and Tricks

Prevent hot linking of images.

Hot linking is displaying an image on a website by linking to the same image on another website, rather than saving a copy of it on the website on which the image will be shown.

Lets say, you have an image at www.yourdomain.com/image.jpg and it is not well protected. If someone links this image to his website as www.someoneelse.com/image.jpg, then it is going to consume both bandwidth and resources of your server when any end user access www.someoneelse.com/image.jpg.

All traffic of such requests will be coming to your server. It will be just like someone is enjoying a free ride and you are paying for it.

Hot linking of websites can be prevented with following simple .htaccess rule placed in the DocumenRoot folder of your website.

RewriteEngine on
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^http(s)?://(www\.)?yourdomain.com [NC]
RewriteRule \.(jpg|jpeg|png|gif)$ – [NC,F,L]

Please remember to replace “yourdomain.com” with your own domain in the above .htaccess.

Related Articles

  • Purging and Loading assets onto your CDN

    Step 1: Login to the Webair EZPanel (https://ezpanel.webair.com) Step 2: On the left side menu, click on CDN.   Step 3: Click on the “Webair CDN” button. This will open up...
  • Disable SELinux

    Security-Enhanced Linux (SELinux) is a mandatory access control (MAC) security mechanism implemented in the Linux kernel. This mechanism adds an extra layer of access security to your files,directories,devices, ports and...
  • Patching The Ghost Vulnerability

    The Ghost vulnerability, also known as CVE-2015-0235, is an exploit in a library named glibc. This library is referenced by many applications which run on your server. The exploit is...
  • Identify the process that is using some specific port

    Sometimes, you may encounter a situation where you see some ports being used by some service, but you cannot exactly determine which application/service is using it. This article talks about how...