Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's true, but sometimes (especially with completely naive or old PHP) 'using prepared statements everywhere' means 'rewriting everything.' In those cases, htaccess might be the only flexible option you have until you can.


Consider ModSecurity with the Core Rule Set (or Trustwave Commercial Rule Set) instead of attempting to repurpose .htaccess files as a substitute WAF.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: