maybe add the following line to be on the safe side: default_type "text/plain"; someone might have an interest in executing scripts otherwise ...