perusio / drupal-with-nginx

Running Drupal using nginx: an idiosyncratically crafted bleeding edge configuration.
855 stars 246 forks source link

Update drupal.conf (yml, md) #289

Open mbomb007 opened 3 years ago

mbomb007 commented 3 years ago

Drupal.conf should be updated to block access to Markdown (.md) and YAML (.yml) files by default. With many modules transitioning to README.md etc instead of README.txt, this change is important for security. Tools like Droopescan can automatically search a site for exposed files to discover which modules are enabled.