Site AI Auditvon Internet Solutions

Directory Listing Enabled? How to Disable It on Any Server

30. August 20268 Min. LesezeitSicherheit & SSL
Directory Listing Enabled? How to Disable It on Any Server

Short answer: Directory listing (also called directory browsing or autoindex) is a web server feature that shows a clickable list of files when a folder has no index page – the familiar “Index of /” page. On a public website it lets anyone browse uploads, backups, logs and plugin folders. Disable it with Options -Indexes in Apache, autoindex off; in Nginx, or the directory browsing setting in IIS or your hosting panel, then check which files were exposed and remove anything sensitive.

Directory listing is one of those settings that nobody enables on purpose but many sites have. It often comes from a default server configuration, a hosting template or an old .htaccess file. On its own it does not break into anything. What it does is hand an attacker – or a curious visitor, or a search engine – a map of your files, including those you assumed nobody would ever find because nothing linked to them. This guide explains the risk, how to check, and how to switch it off on the most common servers.

What directory listing looks like

When a browser requests a folder, such as https://example.com/wp-content/uploads/2024/, the server looks for an index file (index.html, index.php and similar). If none exists and directory listing is enabled, the server generates a page titled “Index of /wp-content/uploads/2024” with every file and subfolder, their sizes and modification dates. If directory listing is disabled, the server returns 403 Forbidden or 404 Not Found instead.

Why it is a risk

How to check your site

  1. Open a few folders directly in the browser, especially ones that usually contain files but no index page: /wp-content/uploads/, /wp-content/plugins/, /images/, /files/, /downloads/, /backup/, /assets/, /media/.
  2. Look for pages titled “Index of” or file listings. A 403 or 404 response means listing is disabled for that folder.
  3. Search for site:example.com intitle:"index of" to see whether search engines have already indexed any listings.
  4. On the server, check the configuration for Options Indexes (Apache) or autoindex on (Nginx), including in .htaccess files and included configuration snippets.

Remember that the setting can differ per folder. One folder with an old .htaccess or a special location block can still expose a listing even when the rest of the site is protected.

How to disable directory listing

How to disable it on Apache

In the virtual host configuration or the main configuration, set:

<Directory /var/www/example>
    Options -Indexes
</Directory>

On shared hosting, add this line to the .htaccess file in your web root:

Options -Indexes

The minus sign removes the Indexes option while keeping other options unchanged. If the server does not allow overriding Options in .htaccess, you will see a 500 error; in that case, ask your host or use the control panel setting. After the change, requesting a folder without an index file should return 403 Forbidden.

How to disable it on Nginx

Nginx disables directory listing by default, but it is often switched on for a specific location, for example a downloads folder. Search the configuration for autoindex and set it to off:

location / {
    autoindex off;
}

Remove any autoindex on; lines that are not deliberately needed, run nginx -t and reload.

IIS, hosting panels and other platforms

Cloud storage buckets: the modern directory listing

Many websites no longer store uploads on the web server itself. Images, downloads and backups live in cloud object storage, served directly or through a CDN. These storage services have their own version of directory listing: a bucket or container configured for public listing returns an XML or JSON index of every object in it when someone requests the bucket’s root address. Publicly listable buckets have been behind a long series of well-publicised data leaks, because the same bucket often holds both public images and private exports.

If your site uses object storage, check three things in the storage settings:

Test by opening the bucket’s base URL in a private window. You should see an access denied message, not a list of files.

The “empty index file” workaround

A common old trick is placing an empty index.html or index.php in each folder, which WordPress does in some of its folders. It works, but only for folders where someone remembered to add the file. New upload folders created each month, plugin folders and backup folders are easily missed. Use the server setting as the real fix, and treat index files only as an extra layer.

After disabling: clean up what was exposed

Turning off listings hides the map, but files remain reachable by their direct URLs, and some may already have been downloaded or indexed. Follow up:

  1. Review what was visible in the listings, especially upload, backup and export folders.
  2. Move backups, exports and logs out of the web root, and delete temporary files.
  3. If personal data or secrets were exposed, assess the impact, change any credentials and check your notification obligations.
  4. Remove indexed listing pages and sensitive files from search results – make them return 404 or 410 and use the search console removal tool for urgent cases.
  5. Protect folders that must hold private files with authentication or serve them through the application with access checks rather than as public files.

When a listing is intentional

Some sites deliberately publish file listings, for example a public software mirror or an open-data folder. That is fine when every file in the folder is meant to be public. Limit listing to that specific folder, never to the web root, and make sure nothing else is ever stored there. Consider a proper download page instead – it gives you control over descriptions, ordering and what is shown.

Quick reference

ServerSetting to disable listingsWhere
Apache / LiteSpeedOptions -IndexesVirtual host, Directory block or .htaccess
Nginxautoindex off;server or location block
IISdirectoryBrowse enabled=”false”IIS Manager or web.config
Hosting panelIndex Manager: No IndexingPer folder or whole site

How Site AI Audit helps

Site AI Audit checks your website from outside, the way visitors, search engines and scanners see it, and reports security findings such as the SSL certificate, HTTPS redirect, security headers and exposed software versions with a plain-language fix for each. Regular re-checks and monitoring on paid plans help you catch configuration changes after server moves or updates, which is when forgotten settings tend to return. Check your site for free.

Related reading

The bottom line

Directory listing turns every folder without an index page into a public file browser. Disable it at the server level – Options -Indexes on Apache, autoindex off on Nginx, the matching setting in IIS or your panel – check a few folders to confirm, and then clean up whatever was exposed. It is a five-minute fix that removes an easy source of leaks and reconnaissance.

FAQ

Is directory listing a vulnerability?

It is a misconfiguration rather than a vulnerability in the software, but it can directly expose sensitive files and helps attackers find weaknesses. Security audits usually rate it as a medium-risk finding, higher if sensitive files are visible.

Will disabling directory listing break my website?

Normally not. Pages and files are still served by their direct URLs; only the automatically generated folder listings disappear. If some feature relied on a listing, replace it with a proper download page.

Does WordPress disable directory listing by itself?

WordPress adds empty index files to some folders, but not to all of them, and it cannot change server settings. Disabling listings in the server configuration or .htaccess is the reliable method.

Why do I get a 500 error after adding Options -Indexes?

Your host does not allow changing Options in .htaccess. Remove the line and disable listings through the hosting control panel or ask the host to do it in the server configuration.

Are files still accessible after I disable listing?

Yes, anyone who knows the exact URL can still open them. Move sensitive files out of the public folder or protect them with access controls, rather than relying on hidden locations.

#Website audit#Website security#WordPress security
Prüfen Sie Ihre eigene Website — kostenlos.Was Sie auf Ihrer Website beheben sollten — und wo Sie anfangen.
Kostenlos starten

Mehr aus dem Blog

Alle Artikel →
Internet Solutions

Mehr von unserem Team

Entwickelt von Internet Solutions. Probieren Sie auch unsere anderen Produkte aus — jedes spart Ihnen auf seine eigene Weise Zeit.

internet-solutions.net ↗
Site AI Audit
Datenschutz-Übersicht

Diese Website verwendet Cookies, damit wir Ihnen die bestmögliche Nutzererfahrung bieten können. Cookie-Informationen werden in Ihrem Browser gespeichert und erfüllen Funktionen wie das Wiedererkennen bei Ihrem nächsten Besuch und helfen unserem Team zu verstehen, welche Bereiche der Website Sie am interessantesten und nützlichsten finden.