{"id":9568,"date":"2026-06-03T06:42:15","date_gmt":"2026-06-03T04:42:15","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=9568"},"modified":"2026-06-03T06:42:16","modified_gmt":"2026-06-03T04:42:16","slug":"how-to-prevent-a-directory-file-listing-from-being-displayed","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-prevent-a-directory-file-listing-from-being-displayed\/","title":{"rendered":"How to Prevent a Directory File Listing from Being Displayed"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">In some situations, accessing a directory directly through a web browser may display a list of all files stored inside it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, visiting:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>https:&#47;&#47;yourdomain.com\/downloads\/<\/code><\/pre>\n\n\n\n<\/div>\n\n<div id=\"mybox-31517076\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">might display all files located in the <code>downloads<\/code> directory if directory listing is enabled.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This behavior can expose files that were not intended to be publicly visible and may create security or privacy concerns.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-prevent-a-directory-file-listing-from-being-displayed\/#Disable_Directory_Listing_with_htaccess\" >Disable Directory Listing with .htaccess<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-prevent-a-directory-file-listing-from-being-displayed\/#Where_Should_the_File_Be_Placed\" >Where Should the File Be Placed?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-prevent-a-directory-file-listing-from-being-displayed\/#What_Happens_After_Adding_the_Rule\" >What Happens After Adding the Rule?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-prevent-a-directory-file-listing-from-being-displayed\/#Applying_the_Rule_to_an_Entire_Website\" >Applying the Rule to an Entire Website<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-prevent-a-directory-file-listing-from-being-displayed\/#Testing_the_Configuration\" >Testing the Configuration<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-prevent-a-directory-file-listing-from-being-displayed\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Disable_Directory_Listing_with_htaccess\"><\/span>Disable Directory Listing with <code>.htaccess<\/code><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To prevent the contents of a directory from being displayed, create or edit a file named:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.htaccess<\/code><\/pre>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> The filename begins with a dot (<code>.<\/code>).<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Add the following rule:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Options -Indexes<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_Should_the_File_Be_Placed\"><\/span>Where Should the File Be Placed?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Place the <code>.htaccess<\/code> file inside the directory you want to protect.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>public_html\/downloads\/.htaccess<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The rule will apply to that directory and, by default, to its subdirectories as well.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Happens_After_Adding_the_Rule\"><\/span>What Happens After Adding the Rule?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When a visitor attempts to access a directory without an index file (such as <code>index.php<\/code> or <code>index.html<\/code>), the server will no longer display the file listing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead, the visitor will typically see:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A <strong>403 Forbidden<\/strong> error<\/li>\n\n\n\n<li>A custom error page, if configured<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Applying_the_Rule_to_an_Entire_Website\"><\/span>Applying the Rule to an Entire Website<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you want to disable directory listing across the entire website, add the rule to the main <code>.htaccess<\/code> file located in the website&#8217;s root directory, for example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>public_html\/.htaccess<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Options -Indexes<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This will prevent directory listings throughout the website unless overridden by another <code>.htaccess<\/code> file.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Testing_the_Configuration\"><\/span>Testing the Configuration<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">After saving the <code>.htaccess<\/code> file:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Open a browser.<\/li>\n\n\n\n<li>Visit a directory that previously displayed a file listing.<\/li>\n\n\n\n<li>Confirm that the list is no longer visible.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">If the directory now returns a 403 error, the configuration is working correctly.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To prevent visitors from viewing the contents of a directory, create or edit a <code>.htaccess<\/code> file and add the following directive:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Options -Indexes<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This disables directory browsing and helps protect files from being exposed through automatic directory listings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[125],"manual_kb_tag":[5211,5212,5213,5214,5215,5216,718,4271,4800,5210],"class_list":["post-9568","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-websites","manual_kb_tag-disable-directory-listing","manual_kb_tag-prevent-directory-listing","manual_kb_tag-options-indexes","manual_kb_tag-disable-directory-browsing","manual_kb_tag-directory-browsing","manual_kb_tag-index-file","manual_kb_tag-htaccess-file","manual_kb_tag-40-forbidden","manual_kb_tag-custom-error-page","manual_kb_tag-directory-listing"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9568","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9568\/revisions"}],"predecessor-version":[{"id":9569,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9568\/revisions\/9569"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=9568"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=9568"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=9568"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}