# Prevent hotlinking

**URL:** <https://community.wowza.com/t/prevent-hotlinking/94629>\
**Category:** Wowza Streaming Engine\
**Created:** [February 22, 2022, 9:42pm UTC](https://community.wowza.com/t/prevent-hotlinking/94629 "2022-02-22T21:42:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Krof\_Krofek](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/krof_krofek/32/1070_2.png) [@Krof\_Krofek](https://community.wowza.com/u/Krof_Krofek)\
**Post date:** [February 22, 2022, 9:42pm UTC](https://community.wowza.com/t/prevent-hotlinking/94629/1 "2022-02-22T21:42:34Z")

</div>

Hello,

Where to put htaccess file with rules to prevent hotlinking to wowza thumbnails http://[wowza-ip-address]:8086/thumbnail?xxx

Thanks

M

---

<div class="post-metadata">

**Author:** ![Karel\_Boek](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/karel_boek/32/454_2.png) [@Karel\_Boek](https://community.wowza.com/u/Karel_Boek)\
**Post date:** [February 24, 2022, 11:21am UTC](https://community.wowza.com/t/prevent-hotlinking/94629/2 "2022-02-24T11:21:55Z")

</div>

.htaccess file are specific to Apache Web Server and don’t work on Wowza Streaming Engine. The easiest is to enable authentication (digest or basic) for the mentioned HTTP provider in the VHost.xml. Alternatively you can put a web proxy in front of your Wowza Server (could be Apache, Nginx, etc) and configure hotlinking there.

There are also other ways to prevent, eg. a more custom implementation with token protection or URL referral checks etc.

---

<div class="post-metadata">

**Author:** ![Connessione](https://avatars.discourse-cdn.com/v4/letter/c/43a26b/32.png) [@Connessione](https://community.wowza.com/u/Connessione)\
**Post date:** [February 24, 2022, 11:35am UTC](https://community.wowza.com/t/prevent-hotlinking/94629/3 "2022-02-24T11:35:29Z")

</div>

As @Karel_Boek rightly mentioned .htaccess won’t work here as this is not regular Apache. Wowza is more or less based off tomcat. In addition to what he mention where a few more things you can opt for.

1. move the image to a different folder on system or to a different system (if applicable) and have it served from a different web server that allows .htaccess

2. Look into [Tuckey URLRewrite](https://tuckey.org/urlrewrite/) that works for most tomcat based servers. It is like the .htaccess of java servers.

3. Perhaps a custom http provider / filter to just control access to the image’s path.
