DNS, Security & Integrations
Disable Directory Browsing on Server
Stop your server from showing a raw file listing when a folder has no index file.
The Problem
Directory browsing left enabled means anyone who finds a folder URL without an index page can see every file in it — sometimes including things that were never meant to be public.
About this problem
When a folder has no index file, some servers return an automatic listing of every file in it. This is controlled by a setting such as Options Indexes in Apache or autoindex in Nginx. If it is left on, anyone who guesses or finds the folder URL can browse its contents, including backups, logs or uploads that were never meant to be linked.
People look for this after a security scan flags 'directory listing enabled', or after noticing a raw file list in the browser. The setting itself is quick to change, but it is worth looking at what was exposed, since the listing may already have been seen or indexed.
What's Included
- Checking which directories currently expose browsable listings
- Disabling directory browsing at the server/.htaccess level
- Verifying normal site functionality is unaffected
- A quick check for anything sensitive that was exposed and should be reviewed
What's NOT Included
- Reviewing or securing the actual contents found (flagged to you, fixed as a separate step if needed)
- Full server hardening beyond this specific setting
- Access control for folders that should remain intentionally browsable
How It Works
- I check the common folders on your site, such as uploads, includes and backups, to see which show browsable listings.
- I identify whether the server is Apache or Nginx and where the relevant setting is controlled.
- I disable directory indexing in .htaccess or the server configuration.
- I re-test the same folders to confirm they now return a forbidden or error response instead of a listing.
- I browse the main parts of the site to confirm that normal pages and assets still load.
- I note any files that look sensitive and tell you so you can review them.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- What is directory browsing?
- It is a server feature that shows a list of the files in a folder when no index page exists. It is usually unwanted on public sites.
- How do I turn off directory listing in Apache?
- By removing or disabling the Indexes option, commonly with Options -Indexes in .htaccess. I do this and check it works.
- Will disabling it break my site?
- Normally not, since pages and assets are still served by their direct URLs. I verify this after the change.
- What if sensitive files were already exposed?
- I will flag anything I notice, but reviewing, removing or securing the contents is a separate step.
- Is this the same as hardening my whole server?
- No. It covers this one setting only, not a wider server security review.
- Can some folders stay browsable?
- Intentionally browsable folders, such as a public downloads index, and access control for them are outside this service.