## Blocking the Tencent ips under monitoring case 43827807 RewriteEngine On RewriteCond %{REMOTE_ADDR} ^43\.173\.(12[8-9]|1[3-9][0-9]|2[0-9]{2})\. RewriteRule ^ - [F,L] Deny from 92.255.57.53 Deny from 154.195.186.212 Deny from 138.124.180.19 ############################################ ## GoDaddy specific options # Options -MultiViews ## you might also need to add this line to php.ini ## cgi.fix_pathinfo = 1 ## if it still doesn't work, rename php.ini to php7.ini ############################################ ## default index file DirectoryIndex index.php ############################################ ## php7 settings ############################################ ## adjust max execution time php_value max_execution_time 18000 ############################################ ## disable automatic session start ## before autoload was initialized php_flag session.auto_start off ############################################ ## enable resulting html compression #php_flag zlib.output_compression on ########################################### # disable user agent verification to not break multiple image upload php_flag suhosin.session.cryptua off ########################################### # disable POST processing to not break multiple image upload SecFilterEngine Off SecFilterScanPOST Off ############################################ ## enable apache served files compression ## http://developer.yahoo.com/performance/rules.html#gzip # Insert filter on all content ###SetOutputFilter DEFLATE # Insert filter on selected content types only #AddOutputFilterByType DEFLATE text/html text/plain text/xml text/css text/javascript # Netscape 4.x has some problems... #BrowserMatch ^Mozilla/4 gzip-only-text/html # Netscape 4.06-4.08 have some more problems #BrowserMatch ^Mozilla/4\.0[678] no-gzip # MSIE masquerades as Netscape, but it is fine #BrowserMatch \bMSIE !no-gzip !gzip-only-text/html # Don't compress images #SetEnvIfNoCase Request_URI \.(?:gif|jpe?g|png)$ no-gzip dont-vary # Make sure proxies don't deliver the wrong content #Header append Vary User-Agent env=!dont-vary ############################################ ## make HTTPS env vars available for CGI mode SSLOptions StdEnvVars ############################################ ## enable rewrites Options +FollowSymLinks RewriteEngine on ############################################ ## redirect to https://www if not already RewriteCond %{HTTP:X-Forwarded-Proto} !https RewriteCond %{HTTPS} off [OR] RewriteCond %{HTTP_HOST} !^www\. [NC] RewriteRule ^ https://www.americanstationery.com%{REQUEST_URI} [R=301,L] ############################################ ## Block access to admin unless from allowed IP addresses RewriteCond %{REQUEST_URI} ^/(index\.php/)?astPortal5(/|$) [NC] RewriteCond %{REMOTE_ADDR} !^149\.154\.23\.18 RewriteCond %{REMOTE_ADDR} !^75\.150\.218\.100 RewriteCond %{REMOTE_ADDR} !^68\.183\.31\.214 RewriteCond %{REMOTE_ADDR} !^46\.110\.52\.245 RewriteCond %{REMOTE_ADDR} !^223\.181\.56\.215 RewriteCond %{REMOTE_ADDR} !^216\.147\.81\.30 RewriteRule ^.*$ - [F,L] ############################################ ## you can put here your magento root folder ## path relative to web root #RewriteBase /magento/ ############################################ ## Prevent serving "hidden" files like git repository RewriteCond %{REQUEST_URI} /\. RewriteRule ^(.*)$ / [R=404,L] ############################################ ## uncomment next line to enable light API calls processing # RewriteRule ^api/([a-z][0-9a-z_]+)/?$ api.php?type=$1 [QSA,L] ############################################ ## rewrite API2 calls to api.php (by now it is REST only) RewriteRule ^api/rest api.php?type=rest [QSA,L] ############################################ ## workaround for HTTP authorization ## in CGI environment RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}] ############################################ ## TRACE and TRACK HTTP methods disabled to prevent XSS attacks RewriteCond %{REQUEST_METHOD} ^TRAC[EK] RewriteRule .* - [L,R=405] ############################################ ## Reject exceptionally large two-filter combinations before Magento boots RewriteCond %{REQUEST_METHOD} =GET RewriteCond %{REQUEST_URI} \.html$ [NC] RewriteCond %{QUERY_STRING} (^|&)card_size= [NC] RewriteCond %{QUERY_STRING} (^|&)colorfilter= [NC] RewriteCond %{QUERY_STRING} ^.{193,}$ RewriteRule .* - [F,L] ############################################ ## Block faceted-navigation abuse on .html pages when 3+ listed filters are present RewriteCond %{REQUEST_METHOD} =GET RewriteCond %{REQUEST_URI} \.html$ [NC] RewriteCond %{QUERY_STRING} (^|.*&)(order|production_time|cardformat|printingtype|pricinglevel|brand|cardstyle|colorfilter|card_size|recipient)=.*(&|$).*(order|production_time|cardformat|printingtype|pricinglevel|brand|cardstyle|colorfilter|card_size|recipient)=.*(&|$).*(order|production_time|cardformat|printingtype|pricinglevel|brand|cardstyle|colorfilter|card_size|recipient)= [NC] RewriteRule .* - [F,L] ############################################ ## Enable Developer Mode based on OS environment variable SetEnvIfExpr "osenv('MAGE_IS_DEVELOPER_MODE') == '1'" MAGE_IS_DEVELOPER_MODE=1 ############################################ # X-Content-Type-Options: nosniff disable content-type sniffing on some browsers. Header set X-Content-Type-Options: nosniff ############################################ # This header forces to enables the Cross-site scripting (XSS) filter in browsers (if disabled) BrowserMatch \bMSIE\s8 ie8 Header set X-XSS-Protection: "1; mode=block" env=!ie8 ############################################ ## redirect for mobile user agents #RewriteCond %{REQUEST_URI} !^/mobiledirectoryhere/.*$ #RewriteCond %{HTTP_USER_AGENT} "android|blackberry|ipad|iphone|ipod|iemobile|opera mobile|palmos|webos|googlebot-mobile" [NC] #RewriteRule ^(.*)$ /mobiledirectoryhere/ [L,R=302] ############################################ ## always send 404 on missing files in these folders RewriteCond %{REQUEST_URI} !^/(media|skin|js)/ ############################################ ## never rewrite for existing files, directories and links RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteCond %{REQUEST_FILENAME} !-l ############################################ ## rewrite everything else to index.php RewriteRule .* index.php [L] ############################################ ## Prevent character encoding issues from server overrides ## If you still have problems, use the second line instead AddDefaultCharset Off #AddDefaultCharset UTF-8 ############################################ ## Add default Expires header ## http://developer.yahoo.com/performance/rules.html#expires ExpiresActive On ExpiresByType image/jpg "access plus 1 year" ExpiresByType image/jpeg "access plus 1 year" ExpiresByType image/gif "access plus 1 year" ExpiresByType image/png "access plus 1 year" ExpiresByType text/css "access plus 1 month" ExpiresByType application/pdf "access plus 1 month" ExpiresByType text/x-javascript "access plus 1 month" ExpiresByType application/x-shockwave-flash "access plus 1 month" ExpiresByType image/x-icon "access plus 1 year" ExpiresDefault "access plus 2 days" ############################################ ## By default allow all access Order allow,deny Allow from all ########################################### ## Deny access to other project files to prevent disclosure of the installed Magento version or other information ## Only robots.txt and manifest.json should be allowed by default Order allow,deny Deny from all Order allow,deny Deny from all Order allow,deny Deny from all ############################################ ## If running in cluster environment, uncomment this ## http://developer.yahoo.com/performance/rules.html#etags #FileETag none ########################################### ## Deny access to cron.php ############################################ ## uncomment next lines to enable cron access with base HTTP authorization ## http://httpd.apache.org/docs/2.2/howto/auth.html ## ## Warning: .htpasswd file should be placed somewhere not accessible from the web. ## This is so that folks cannot download the password file. ## For example, if your documents are served out of /usr/local/apache/htdocs ## you might want to put the password file(s) in /usr/local/apache/. #AuthName "Cron auth" #AuthUserFile ../.htpasswd #AuthType basic #Require valid-user ############################################ Order allow,deny Deny from all