diff --git a/.htaccess b/.htaccess
new file mode 100644
index 0000000000..a88faa7f13
--- /dev/null
+++ b/.htaccess
@@ -0,0 +1,15 @@
+# disable directory listing
+Options -Indexes
+
+# disable file serving (Apache 2.4)
+
+ Require all denied
+
+
+# disable file serving (Apache 2.2)
+
+
+ Order deny,allow
+ Deny from all
+
+
diff --git a/assets/.htaccess b/assets/.htaccess
new file mode 100644
index 0000000000..117f7eb8dd
--- /dev/null
+++ b/assets/.htaccess
@@ -0,0 +1,12 @@
+# enable file serving (Apache 2.4)
+
+ Require all granted
+
+
+# enable file serving (Apache 2.2)
+
+
+ Order allow,deny
+ Allow from all
+
+