This guide follows the same hardening strategy: set proper file permissions first, then apply webserver rules to block unauthorized access, prevent PHP execution inside upload folders and protect sensitive configuration files.
Never use global 777 permissions.
- Regular folders: 755
- Static files (php, tpl, twig, css, js): 644
- Folders requiring write access (only these):/img/, /upload/, /var/cache/, /var/logs/, /var/uploads/Set these writable…