Protecting Sensitive Files

Protecting .env, Config Files, Backups and Dot Directories

Scanners probe every site for /.env and /.git/config; in 2024 Palo Alto Networks' Unit 42 described an extortion campaign that targeted 110,000 domains through exposed .env files. Keep such files out of the document root, as Laravel 2,157 's public/ does (Laravel); this is the safety net:

Refusing dot files, backups, manifests and vendor codeApache config
# /var/www/example/.htaccess - Needs: mod_alias; AllowOverride AuthConfig FileInfo
RedirectMatch 404 "/\.(?!well-known/)"
<FilesMatch "(?i)(\.(bak|old|orig|save|swp|tmp|dist|sql|sqlite|log|ini)|~)$">
  Require all denied
</FilesMatch>
<FilesMatch "^(composer\.(json|lock)|package(-lock)?\.json|phpunit\.xml|Dockerfile)$">
  Require all denied
</FilesMatch>
RedirectMatch 404 "^/(vendor|node_modules)/"

The usual <FilesMatch "^\."> fails, since it sees only a file's own name: /.env got 403, but /.git/config and /.git/HEAD got 200. Line 2 tests the URL and answers 404, leaving /.well-known/ to Let's Encrypt 1,144 . Lines 3 to 8 refuse backups, dumps and manifests in any case, whatever URL reaches them (Directory, Files, Location), and line 9 hides included libraries:

Output of 69
/.env                            404
/.git/config                     404
/.well-known/acme-challenge/tok  200
/config.php.bak                  403
/index.php~                      403
/error.LOG                       403
/vendor/autoload.php             404
/index.php                       200

Before line 3, config.php.bak came back as PHP source, database password included, because .bak is not a PHP extension. A Hardening Block for Any Site merges this block into a full hardening file.