someone managed to upload php file under images folder and used it to hack my server, can you please tell me the best way to disable php uploads or disable execution of them thanks
From memory, the .htaccess file you create is placed in the uploads directory, not the root directory - I'd also suggest backing up your existing installation first or clearing the cache afterwards.