(02-08-2011 02:52 PM)ZiNgA BuRgA Wrote: I do not recommend using the above.
why not?
Let's say that one installs a plugin that has a security issue.
Majority of users won't ever notice and find eg. XSS in plugin code, so htaccess will protect the forum no matter of the sec hole. Surely, these queries may be bypassed, but better any protection than nothing.
There are many sites with sqli. Some of them, when one tries to put the query just loop and never end wih loading even they are vulnerable. Or, even there's a visible sql error, the query can't be executed because htaccess forbidds it.