Translations:Manual:Security/165/en

If you do accomplish this via a config file in the images directory itself, you should ensure the config file is not writable by the webserver.