Guest User

Untitled

a guest
Jul 9th, 2015
297
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 13.32 KB | None | 0 0
  1. # BEGIN iThemes Security
  2. #Quick ban IP. Will be updated on next formal rules save.
  3. SetEnvIF REMOTE_ADDR "^89\.205\.90\.117$" DenyAccess
  4. SetEnvIF X-FORWARDED-FOR "^89\.205\.90\.117$" DenyAccess
  5. SetEnvIF X-CLUSTER-CLIENT-IP "^89\.205\.90\.117$" DenyAccess
  6. order allow,deny
  7. deny from env=DenyAccess
  8. deny from 89.205.90.117
  9. allow from all
  10. #Quick ban IP. Will be updated on next formal rules save.
  11. SetEnvIF REMOTE_ADDR "^76\.164\.199\.157$" DenyAccess
  12. SetEnvIF X-FORWARDED-FOR "^76\.164\.199\.157$" DenyAccess
  13. SetEnvIF X-CLUSTER-CLIENT-IP "^76\.164\.199\.157$" DenyAccess
  14. order allow,deny
  15. deny from env=DenyAccess
  16. deny from 76.164.199.157
  17. allow from all
  18. # BEGIN Ban Users
  19. # Begin HackRepair.com Blacklist
  20. RewriteEngine on
  21. RewriteCond %{HTTP_USER_AGENT} ^[Ww]eb[Bb]andit [NC,OR]
  22. RewriteCond %{HTTP_USER_AGENT} ^Acunetix [NC,OR]
  23. RewriteCond %{HTTP_USER_AGENT} ^binlar [NC,OR]
  24. RewriteCond %{HTTP_USER_AGENT} ^BlackWidow [NC,OR]
  25. RewriteCond %{HTTP_USER_AGENT} ^Bolt\ 0 [NC,OR]
  26. RewriteCond %{HTTP_USER_AGENT} ^Bot\ mailto:craftbot\@yahoo\.com [NC,OR]
  27. RewriteCond %{HTTP_USER_AGENT} ^BOT\ for\ JCE [NC,OR]
  28. RewriteCond %{HTTP_USER_AGENT} ^casper [NC,OR]
  29. RewriteCond %{HTTP_USER_AGENT} ^checkprivacy [NC,OR]
  30. RewriteCond %{HTTP_USER_AGENT} ^ChinaClaw [NC,OR]
  31. RewriteCond %{HTTP_USER_AGENT} ^clshttp [NC,OR]
  32. RewriteCond %{HTTP_USER_AGENT} ^cmsworldmap [NC,OR]
  33. RewriteCond %{HTTP_USER_AGENT} ^comodo [NC,OR]
  34. RewriteCond %{HTTP_USER_AGENT} ^Custo [NC,OR]
  35. RewriteCond %{HTTP_USER_AGENT} ^Default\ Browser\ 0 [NC,OR]
  36. RewriteCond %{HTTP_USER_AGENT} ^diavol [NC,OR]
  37. RewriteCond %{HTTP_USER_AGENT} ^DIIbot [NC,OR]
  38. RewriteCond %{HTTP_USER_AGENT} ^DISCo [NC,OR]
  39. RewriteCond %{HTTP_USER_AGENT} ^dotbot [NC,OR]
  40. RewriteCond %{HTTP_USER_AGENT} ^Download\ Demon [NC,OR]
  41. RewriteCond %{HTTP_USER_AGENT} ^eCatch [NC,OR]
  42. RewriteCond %{HTTP_USER_AGENT} ^EirGrabber [NC,OR]
  43. RewriteCond %{HTTP_USER_AGENT} ^EmailCollector [NC,OR]
  44. RewriteCond %{HTTP_USER_AGENT} ^EmailSiphon [NC,OR]
  45. RewriteCond %{HTTP_USER_AGENT} ^EmailWolf [NC,OR]
  46. RewriteCond %{HTTP_USER_AGENT} ^Express\ WebPictures [NC,OR]
  47. RewriteCond %{HTTP_USER_AGENT} ^extract [NC,OR]
  48. RewriteCond %{HTTP_USER_AGENT} ^ExtractorPro [NC,OR]
  49. RewriteCond %{HTTP_USER_AGENT} ^EyeNetIE [NC,OR]
  50. RewriteCond %{HTTP_USER_AGENT} ^feedfinder [NC,OR]
  51. RewriteCond %{HTTP_USER_AGENT} ^FHscan [NC,OR]
  52. RewriteCond %{HTTP_USER_AGENT} ^FlashGet [NC,OR]
  53. RewriteCond %{HTTP_USER_AGENT} ^flicky [NC,OR]
  54. RewriteCond %{HTTP_USER_AGENT} ^GetRight [NC,OR]
  55. RewriteCond %{HTTP_USER_AGENT} ^GetWeb! [NC,OR]
  56. RewriteCond %{HTTP_USER_AGENT} ^Go-Ahead-Got-It [NC,OR]
  57. RewriteCond %{HTTP_USER_AGENT} ^g00g1e [NC,OR]
  58. RewriteCond %{HTTP_USER_AGENT} ^Go!Zilla [NC,OR]
  59. RewriteCond %{HTTP_USER_AGENT} ^grab [NC,OR]
  60. RewriteCond %{HTTP_USER_AGENT} ^GrabNet [NC,OR]
  61. RewriteCond %{HTTP_USER_AGENT} ^Grafula [NC,OR]
  62. RewriteCond %{HTTP_USER_AGENT} ^harvest [NC,OR]
  63. RewriteCond %{HTTP_USER_AGENT} ^HMView [NC,OR]
  64. RewriteCond %{HTTP_USER_AGENT} ^ia_archiver [NC,OR]
  65. RewriteCond %{HTTP_USER_AGENT} ^Image\ Stripper [NC,OR]
  66. RewriteCond %{HTTP_USER_AGENT} ^Image\ Sucker [NC,OR]
  67. RewriteCond %{HTTP_USER_AGENT} ^InterGET [NC,OR]
  68. RewriteCond %{HTTP_USER_AGENT} ^Internet\ Ninja [NC,OR]
  69. RewriteCond %{HTTP_USER_AGENT} ^InternetSeer\.com [NC,OR]
  70. RewriteCond %{HTTP_USER_AGENT} ^jakarta [NC,OR]
  71. RewriteCond %{HTTP_USER_AGENT} ^Java [NC,OR]
  72. RewriteCond %{HTTP_USER_AGENT} ^JetCar [NC,OR]
  73. RewriteCond %{HTTP_USER_AGENT} ^JOC\ Web\ Spider [NC,OR]
  74. RewriteCond %{HTTP_USER_AGENT} ^kanagawa [NC,OR]
  75. RewriteCond %{HTTP_USER_AGENT} ^kmccrew [NC,OR]
  76. RewriteCond %{HTTP_USER_AGENT} ^larbin [NC,OR]
  77. RewriteCond %{HTTP_USER_AGENT} ^LeechFTP [NC,OR]
  78. RewriteCond %{HTTP_USER_AGENT} ^libwww [NC,OR]
  79. RewriteCond %{HTTP_USER_AGENT} ^Mass\ Downloader [NC,OR]
  80. RewriteCond %{HTTP_USER_AGENT} ^Maxthon$ [NC,OR]
  81. RewriteCond %{HTTP_USER_AGENT} ^microsoft\.url [NC,OR]
  82. RewriteCond %{HTTP_USER_AGENT} ^MIDown\ tool [NC,OR]
  83. RewriteCond %{HTTP_USER_AGENT} ^miner [NC,OR]
  84. RewriteCond %{HTTP_USER_AGENT} ^Mister\ PiX [NC,OR]
  85. RewriteCond %{HTTP_USER_AGENT} ^Mozilla\.*Indy [NC,OR]
  86. RewriteCond %{HTTP_USER_AGENT} ^Mozilla\.*NEWT [NC,OR]
  87. RewriteCond %{HTTP_USER_AGENT} ^MSFrontPage [NC,OR]
  88. RewriteCond %{HTTP_USER_AGENT} ^Navroad [NC,OR]
  89. RewriteCond %{HTTP_USER_AGENT} ^NearSite [NC,OR]
  90. RewriteCond %{HTTP_USER_AGENT} ^Net\ Vampire [NC,OR]
  91. RewriteCond %{HTTP_USER_AGENT} ^NetAnts [NC,OR]
  92. RewriteCond %{HTTP_USER_AGENT} ^NetSpider [NC,OR]
  93. RewriteCond %{HTTP_USER_AGENT} ^NetZIP [NC,OR]
  94. RewriteCond %{HTTP_USER_AGENT} ^nutch [NC,OR]
  95. RewriteCond %{HTTP_USER_AGENT} ^Octopus [NC,OR]
  96. RewriteCond %{HTTP_USER_AGENT} ^Offline\ Explorer [NC,OR]
  97. RewriteCond %{HTTP_USER_AGENT} ^Offline\ Navigator [NC,OR]
  98. RewriteCond %{HTTP_USER_AGENT} ^PageGrabber [NC,OR]
  99. RewriteCond %{HTTP_USER_AGENT} ^Papa\ Foto [NC,OR]
  100. RewriteCond %{HTTP_USER_AGENT} ^pavuk [NC,OR]
  101. RewriteCond %{HTTP_USER_AGENT} ^pcBrowser [NC,OR]
  102. RewriteCond %{HTTP_USER_AGENT} ^PeoplePal [NC,OR]
  103. RewriteCond %{HTTP_USER_AGENT} ^planetwork [NC,OR]
  104. RewriteCond %{HTTP_USER_AGENT} ^psbot [NC,OR]
  105. RewriteCond %{HTTP_USER_AGENT} ^purebot [NC,OR]
  106. RewriteCond %{HTTP_USER_AGENT} ^pycurl [NC,OR]
  107. RewriteCond %{HTTP_USER_AGENT} ^RealDownload [NC,OR]
  108. RewriteCond %{HTTP_USER_AGENT} ^ReGet [NC,OR]
  109. RewriteCond %{HTTP_USER_AGENT} ^Rippers\ 0 [NC,OR]
  110. RewriteCond %{HTTP_USER_AGENT} ^SeaMonkey$ [NC,OR]
  111. RewriteCond %{HTTP_USER_AGENT} ^sitecheck\.internetseer\.com [NC,OR]
  112. RewriteCond %{HTTP_USER_AGENT} ^SiteSnagger [NC,OR]
  113. RewriteCond %{HTTP_USER_AGENT} ^skygrid [NC,OR]
  114. RewriteCond %{HTTP_USER_AGENT} ^SmartDownload [NC,OR]
  115. RewriteCond %{HTTP_USER_AGENT} ^sucker [NC,OR]
  116. RewriteCond %{HTTP_USER_AGENT} ^SuperBot [NC,OR]
  117. RewriteCond %{HTTP_USER_AGENT} ^SuperHTTP [NC,OR]
  118. RewriteCond %{HTTP_USER_AGENT} ^Surfbot [NC,OR]
  119. RewriteCond %{HTTP_USER_AGENT} ^tAkeOut [NC,OR]
  120. RewriteCond %{HTTP_USER_AGENT} ^Teleport\ Pro [NC,OR]
  121. RewriteCond %{HTTP_USER_AGENT} ^Toata\ dragostea\ mea\ pentru\ diavola [NC,OR]
  122. RewriteCond %{HTTP_USER_AGENT} ^turnit [NC,OR]
  123. RewriteCond %{HTTP_USER_AGENT} ^vikspider [NC,OR]
  124. RewriteCond %{HTTP_USER_AGENT} ^VoidEYE [NC,OR]
  125. RewriteCond %{HTTP_USER_AGENT} ^Web\ Image\ Collector [NC,OR]
  126. RewriteCond %{HTTP_USER_AGENT} ^Web\ Sucker [NC,OR]
  127. RewriteCond %{HTTP_USER_AGENT} ^WebAuto [NC,OR]
  128. RewriteCond %{HTTP_USER_AGENT} ^WebCopier [NC,OR]
  129. RewriteCond %{HTTP_USER_AGENT} ^WebFetch [NC,OR]
  130. RewriteCond %{HTTP_USER_AGENT} ^WebGo\ IS [NC,OR]
  131. RewriteCond %{HTTP_USER_AGENT} ^WebLeacher [NC,OR]
  132. RewriteCond %{HTTP_USER_AGENT} ^WebReaper [NC,OR]
  133. RewriteCond %{HTTP_USER_AGENT} ^WebSauger [NC,OR]
  134. RewriteCond %{HTTP_USER_AGENT} ^WPScan [NC,OR]
  135. RewriteCond %{HTTP_USER_AGENT} ^Website\ eXtractor [NC,OR]
  136. RewriteCond %{HTTP_USER_AGENT} ^Website\ Quester [NC,OR]
  137. RewriteCond %{HTTP_USER_AGENT} ^WebStripper [NC,OR]
  138. RewriteCond %{HTTP_USER_AGENT} ^WebWhacker [NC,OR]
  139. RewriteCond %{HTTP_USER_AGENT} ^WebZIP [NC,OR]
  140. RewriteCond %{HTTP_USER_AGENT} ^Wget [NC,OR]
  141. RewriteCond %{HTTP_USER_AGENT} ^Widow [NC,OR]
  142. RewriteCond %{HTTP_USER_AGENT} ^WWW-Mechanize [NC,OR]
  143. RewriteCond %{HTTP_USER_AGENT} ^WWWOFFLE [NC,OR]
  144. RewriteCond %{HTTP_USER_AGENT} ^Xaldon\ WebSpider [NC,OR]
  145. RewriteCond %{HTTP_USER_AGENT} ^Yandex [NC,OR]
  146. RewriteCond %{HTTP_USER_AGENT} ^Zeus [NC,OR]
  147. RewriteCond %{HTTP_USER_AGENT} ^zmeu [NC,OR]
  148. RewriteCond %{HTTP_USER_AGENT} AhrefsBot [NC,OR]
  149. RewriteCond %{HTTP_USER_AGENT} CazoodleBot [NC,OR]
  150. RewriteCond %{HTTP_USER_AGENT} discobot [NC,OR]
  151. RewriteCond %{HTTP_USER_AGENT} ecxi [NC,OR]
  152. RewriteCond %{HTTP_USER_AGENT} GT::WWW [NC,OR]
  153. RewriteCond %{HTTP_USER_AGENT} heritrix [NC,OR]
  154. RewriteCond %{HTTP_USER_AGENT} HTTP::Lite [NC,OR]
  155. RewriteCond %{HTTP_USER_AGENT} HTTrack [NC,OR]
  156. RewriteCond %{HTTP_USER_AGENT} ia_archiver [NC,OR]
  157. RewriteCond %{HTTP_USER_AGENT} id-search [NC,OR]
  158. RewriteCond %{HTTP_USER_AGENT} id-search\.org [NC,OR]
  159. RewriteCond %{HTTP_USER_AGENT} IDBot [NC,OR]
  160. RewriteCond %{HTTP_USER_AGENT} Indy\ Library [NC,OR]
  161. RewriteCond %{HTTP_USER_AGENT} IRLbot [NC,OR]
  162. RewriteCond %{HTTP_USER_AGENT} ISC\ Systems\ iRc\ Search\ 2\.1 [NC,OR]
  163. RewriteCond %{HTTP_USER_AGENT} LinksManager.com_bot [NC,OR]
  164. RewriteCond %{HTTP_USER_AGENT} linkwalker [NC,OR]
  165. RewriteCond %{HTTP_USER_AGENT} lwp-trivial [NC,OR]
  166. RewriteCond %{HTTP_USER_AGENT} MFC_Tear_Sample [NC,OR]
  167. RewriteCond %{HTTP_USER_AGENT} Microsoft\ URL\ Control [NC,OR]
  168. RewriteCond %{HTTP_USER_AGENT} Missigua\ Locator [NC,OR]
  169. RewriteCond %{HTTP_USER_AGENT} MJ12bot [NC,OR]
  170. RewriteCond %{HTTP_USER_AGENT} panscient.com [NC,OR]
  171. RewriteCond %{HTTP_USER_AGENT} PECL::HTTP [NC,OR]
  172. RewriteCond %{HTTP_USER_AGENT} PHPCrawl [NC,OR]
  173. RewriteCond %{HTTP_USER_AGENT} PleaseCrawl [NC,OR]
  174. RewriteCond %{HTTP_USER_AGENT} SBIder [NC,OR]
  175. RewriteCond %{HTTP_USER_AGENT} Snoopy [NC,OR]
  176. RewriteCond %{HTTP_USER_AGENT} Steeler [NC,OR]
  177. RewriteCond %{HTTP_USER_AGENT} URI::Fetch [NC,OR]
  178. RewriteCond %{HTTP_USER_AGENT} urllib [NC,OR]
  179. RewriteCond %{HTTP_USER_AGENT} Web\ Sucker [NC,OR]
  180. RewriteCond %{HTTP_USER_AGENT} webalta [NC,OR]
  181. RewriteCond %{HTTP_USER_AGENT} WebCollage [NC,OR]
  182. RewriteCond %{HTTP_USER_AGENT} Wells\ Search\ II [NC,OR]
  183. RewriteCond %{HTTP_USER_AGENT} WEP\ Search [NC,OR]
  184. RewriteCond %{HTTP_USER_AGENT} zermelo [NC,OR]
  185. RewriteCond %{HTTP_USER_AGENT} ZyBorg [NC]
  186. RewriteRule ^.* - [F,L]
  187. # End HackRepair.com Blacklist, http://pastebin.com/u/hackrepair
  188. SetEnvIF REMOTE_ADDR "^159\.224\.139\.133$" DenyAccess
  189. SetEnvIF X-FORWARDED-FOR "^159\.224\.139\.133$" DenyAccess
  190. SetEnvIF X-CLUSTER-CLIENT-IP "^159\.224\.139\.133$" DenyAccess
  191.  
  192. order allow,deny
  193. deny from env=DenyAccess
  194. deny from 159.224.139.133
  195. allow from all
  196.  
  197. # END Ban Users
  198. # BEGIN Hide Backend
  199. # Rules to hide the dashboard
  200. RewriteRule ^(/)?mylogin/?$ /wp-login.php [QSA,L]
  201.  
  202. # END Hide Backend
  203. # BEGIN Tweaks
  204. # Rules to block access to WordPress specific files
  205. <files .htaccess>
  206. Order allow,deny
  207. Deny from all
  208. </files>
  209. <files readme.html>
  210. Order allow,deny
  211. Deny from all
  212. </files>
  213. <files readme.txt>
  214. Order allow,deny
  215. Deny from all
  216. </files>
  217. <files install.php>
  218. Order allow,deny
  219. Deny from all
  220. </files>
  221. <files wp-config.php>
  222. Order allow,deny
  223. Deny from all
  224. </files>
  225.  
  226. # Rules to disable XML-RPC
  227. <files xmlrpc.php>
  228. Order allow,deny
  229. Deny from all
  230. </files>
  231.  
  232. # Rules to disable directory browsing
  233. Options -Indexes
  234.  
  235. <IfModule mod_rewrite.c>
  236. RewriteEngine On
  237.  
  238. # Rules to protect wp-includes
  239.  
  240. RewriteRule ^wp-admin/includes/ - [F]
  241. RewriteRule !^wp-includes/ - [S=3]
  242. RewriteCond %{SCRIPT_FILENAME} !^(.*)wp-includes/ms-files.php
  243. RewriteRule ^wp-includes/[^/]+\.php$ - [F]
  244. RewriteRule ^wp-includes/js/tinymce/langs/.+\.php - [F]
  245. RewriteRule ^wp-includes/theme-compat/ - [F]
  246.  
  247. # Rules to prevent php execution in uploads
  248. RewriteRule ^(.*)/uploads/(.*).php(.?) - [F]
  249.  
  250. # Rules to block unneeded HTTP methods
  251. RewriteCond %{REQUEST_METHOD} ^(TRACE|DELETE|TRACK) [NC]
  252. RewriteRule ^(.*)$ - [F]
  253.  
  254. # Rules to block suspicious URIs
  255. RewriteCond %{QUERY_STRING} \.\.\/ [NC,OR]
  256. RewriteCond %{QUERY_STRING} ^.*\.(bash|git|hg|log|svn|swp|cvs) [NC,OR]
  257. RewriteCond %{QUERY_STRING} etc/passwd [NC,OR]
  258. RewriteCond %{QUERY_STRING} boot\.ini [NC,OR]
  259. RewriteCond %{QUERY_STRING} ftp\: [NC,OR]
  260. RewriteCond %{QUERY_STRING} http\: [NC,OR]
  261. RewriteCond %{QUERY_STRING} https\: [NC,OR]
  262. RewriteCond %{QUERY_STRING} (\<|%3C).*script.*(\>|%3E) [NC,OR]
  263. RewriteCond %{QUERY_STRING} mosConfig_[a-zA-Z_]{1,21}(=|%3D) [NC,OR]
  264. RewriteCond %{QUERY_STRING} base64_encode.*\(.*\) [NC,OR]
  265. RewriteCond %{QUERY_STRING} ^.*(%24&x).* [NC,OR]
  266. RewriteCond %{QUERY_STRING} ^.*(127\.0).* [NC,OR]
  267. RewriteCond %{QUERY_STRING} ^.*(globals|encode|localhost|loopback).* [NC,OR]
  268. RewriteCond %{QUERY_STRING} ^.*(request|concat|insert|union|declare).* [NC]
  269. RewriteCond %{QUERY_STRING} !^loggedout=true
  270. RewriteCond %{QUERY_STRING} !^action=jetpack-sso
  271. RewriteCond %{QUERY_STRING} !^action=rp
  272. RewriteCond %{HTTP_COOKIE} !^.*wordpress_logged_in_.*$
  273. RewriteCond %{HTTP_REFERER} !^http://maps\.googleapis\.com(.*)$
  274. RewriteRule ^(.*)$ - [F]
  275. </IfModule>
  276. # END Tweaks
  277. # END iThemes Security
  278. # BEGIN GzipWpFastestCache
  279. <IfModule mod_deflate.c>
  280. AddOutputFilterByType DEFLATE image/svg+xml
  281. AddOutputFilterByType DEFLATE text/plain
  282. AddOutputFilterByType DEFLATE text/html
  283. AddOutputFilterByType DEFLATE text/xml
  284. AddOutputFilterByType DEFLATE text/css
  285. AddOutputFilterByType DEFLATE application/xml
  286. AddOutputFilterByType DEFLATE application/xhtml+xml
  287. AddOutputFilterByType DEFLATE application/rss+xml
  288. AddOutputFilterByType DEFLATE application/javascript
  289. AddOutputFilterByType DEFLATE application/x-javascript
  290. AddOutputFilterByType DEFLATE application/x-font-ttf
  291. AddOutputFilterByType DEFLATE application/vnd.ms-fontobject
  292. AddOutputFilterByType DEFLATE font/opentype font/ttf font/eot font/otf
  293. </IfModule>
  294. # END GzipWpFastestCache
  295. # BEGIN WordPress
  296. <IfModule mod_rewrite.c>
  297. RewriteEngine On
  298. RewriteBase /
  299. RewriteRule ^index\.php$ - [L]
  300. RewriteCond %{REQUEST_FILENAME} !-f
  301. RewriteCond %{REQUEST_FILENAME} !-d
  302. RewriteRule . /index.php [L]
  303. </IfModule>
  304. # END WordPress
Add Comment
Please, Sign In to add comment