For a directory URL, mod_dir serves the first file in the DirectoryIndex list that exists; if none does and Options Indexes is on, mod_autoindex generates a listing. Ubuntu 225 's dir.conf lists index.html index.cgi index.pl index.php index.xhtml index.htm, and apache2.conf turns Indexes on for /var/www/. On the test site, /files/ therefore returned an "Index of /files" page linking db-backup.sql, notes.txt and report-2026-q3.csv: the backup was one click away. Three lines fix it:
# /var/www/example/.htaccess: index files, and no listings
# Needs: mod_dir; AllowOverride FileInfo Indexes Options=Indexes
ErrorDocument 403 /errors/403.html
DirectoryIndex index.php index.html
Options -Indexes/files/ 403 <!doctype html> <title>Forbidden</ /docs/ 200 docs/index.php /docs/old/ 403 <!doctype html> <title>Forbidden</ /files 301 <!DOCTYPE HTML PUBLIC "-//W3C//DTD
Each line is a URL, its status and the first body bytes. /files/ gets the custom 403. /docs/ holds both index files and serves index.php. /docs/old/ holds only index.htm: a DirectoryIndex in .htaccess replaces the inherited list. /files got a 301 to the slashed form from DirectorySlash; leave it on. Without the Indexes class, line 4 gave a 500.
Keep the minus sign in Options -Indexes: a bare Options Indexes replaces the inherited set and drops FollowSymLinks, which mod_rewrite needs (URL Rewriting with mod_rewrite).