Default Deny Policy

To ensure that a default deny policy is in place on the web server, use the following configuration block:

<Directory /> Order Deny,Allow Deny from all </Directory>

Appropriate access control blocks should then be added to the configuration file to enable access to specific files and directories explicitly. This will ensure that any nonpublic files and directories accidentally left on the web server are not leaked onto the Internet. Do not use this to protect sensitive files, but more as an insurance setting. Don't place unnecessary files, directories, and information onto production systems to start with, and don't store temporary files created by the web application within the webspace of the web server.

