# MOHIRA - Uploads Defense in Depth
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule \.(php|phtml|phar|php[0-9]?|pht|inc|pl|py|jsp|asp|aspx|cgi|sh|exe|bat)$ - [F,L,NC]
RewriteCond %{REQUEST_URI} \.php\. [NC]
RewriteRule .* - [F,L]
RewriteRule (^\.|/\.) - [F,L]
</IfModule>
<IfModule mod_php.c>
php_flag engine off
</IfModule>
<IfModule mod_php5.c>
php_flag engine off
</IfModule>
<IfModule mod_php7.c>
php_flag engine off
</IfModule>
<IfModule mod_php8.c>
php_flag engine off
</IfModule>
<FilesMatch "\.(php|phtml|phar|php[0-9]?|pht|pl|py|jsp|asp|aspx|cgi|sh|exe|bat)$">
<IfModule mod_authz_core.c>
Require all denied
</IfModule>
<IfModule !mod_authz_core.c>
Order Allow,Deny
Deny from all
</IfModule>
</FilesMatch>
Options -Indexes
<IfModule mod_mime.c>
AddType image/jpeg .jpg .jpeg
AddType image/png .png
AddType image/webp .webp
AddType video/mp4 .mp4
AddType video/webm .webm
</IfModule>
<IfModule mod_headers.c>
Header set X-Content-Type-Options "nosniff"
</IfModule>
