Turn off server-level directory listings.
Open IIS Manager, select the directory, double-click , then click Disable in the Actions pane. You can also set it via web.config :
When private images are exposed via an updated directory index, the consequences can be devastating for both individuals and businesses. Data Privacy Violations
What are you running? (Apache, Nginx, IIS?) Where are your images currently stored ? What programming language does your backend use?
