.htaccess redirect - Is it secure?
Posted
by thecrandallster
on Server Fault
See other posts from Server Fault
or by thecrandallster
Published on 2009-11-18T20:35:05Z
Indexed on
2010/04/10
5:03 UTC
Read the original article
Hit count: 323
This works; I'm not having trouble, but I want to be certain that this is bulletproof.
I came up with a neat little .htaccess redirect, but I am not sure if it is secure; do you know?
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule ^goto/([a-z]+)/?$ /$1/ [R]
</IfModule>
I think as long as the server is configured correctly and the files handle authentication autonomously, then it shouldn't be a security issue. Also, being that the rewrite rule only works with characters a-z and one slash I doubt they could jump around directories by injecting stuff into the URL I think...
© Server Fault or respective owner