# File inspired from getgrav/grav # SPDX-License-Identifier: MIT (Copyright 2021 Grav) RewriteEngine On ## Begin - Exploits # If you experience problems on your site block out the operations listed below # This attempts to block the most common type of exploit `attempts` # # Block out any script trying to use twig tags in URL. RewriteCond %{REQUEST_URI} ({{|}}|{%|%}) [OR] RewriteCond %{QUERY_STRING} ({{|}}|{%25|%25}) [OR] # Block out any script trying to base64_encode data within the URL. RewriteCond %{QUERY_STRING} base64_encode[^(]*\([^)]*\) [OR] # Block out any script that includes a