Results 1 to 10 of 10

Thread: More secure default settings - apache, php, ftp [Various Cases]

  1. #1
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Dec 2004
    Posts
    392

    Default More secure default settings - apache, php, ftp [Various Cases]

    Can we have the default settings for Apache, PHP and FTP set more securely.

    Apache
    TraceEnable = OFF
    ServerSignature = OFF
    ServerTokens = ProductOnly
    Directory '/' Options = disable INDEXES

    PHP
    expose_php = OFF


    FTP
    Allow Anonymous Logins = OFF
    Allow Anonymous Uploads = OFF
    Allow Logins with Root Password = OFF
    UK Managed Hosting
    UK Linux Support
    The information given above is intended to be advice only.

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Dec 2004
    Posts
    392

    Default Make FTP secure on build - disable Anonymous (Case 55551)

    Please make Pure-FTP more secure when cPanel is first installed :

    Code:
    Allow Anonymous Logins          NO
    Allow Anonymous Uploads         NO
    Allow Logins with Root Password NO
    These values make it more secure.
    UK Managed Hosting
    UK Linux Support
    The information given above is intended to be advice only.

  3. #3
    Member
    Join Date
    Jan 2008
    Location
    Buenos Aires, Argentina
    Posts
    986
    cPanel/WHM Access Level

    Root Administrator

    Default re: Make FTP secure on build - disable Anonymous (Case 55551)

    I recently buy a VPS with cPanel and this options enabled by default looked like a nonsense.
    So yes, +1 for this

  4. #4
    Member
    Join Date
    Jun 2006
    Location
    Portugal
    Posts
    138
    cPanel/WHM Access Level

    DataCenter Provider

    Default re: Make FTP secure on build - disable Anonymous (Case 55551)

    Agree with this change!
    Sampling Line - Serviços e Internet, Lda.
    PTServidor®
    Blog Oficial | Facebook | MS Partner | R1Soft

  5. #5
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,307
    cPanel/WHM Access Level

    Root Administrator

    Default re: More secure default settings - apache, php, ftp [Various Cases]

    Quote Originally Posted by forlinuxsupport View Post
    Can we have the default settings for Apache, PHP and FTP set more securely.

    Apache
    TraceEnable = OFF
    ServerSignature = OFF
    ServerTokens = ProductOnly
    Directory '/' Options = disable INDEXES

    PHP
    expose_php = OFF
    For those interested, the above are being handled as part of Case 56044

    Quote Originally Posted by forlinuxsupport View Post
    FTP
    Allow Anonymous Logins = OFF
    Allow Anonymous Uploads = OFF
    Allow Logins with Root Password = OFF
    EDIT: These are being handled via Case 58962

  6. #6
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,307
    cPanel/WHM Access Level

    Root Administrator

    Default Re: Make FTP secure on build - disable Anonymous (Case 55551)

    I am going to merge this with the OP's other thread on this topic as to reduce confusion when people search for this feature request.

  7. #7
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,307
    cPanel/WHM Access Level

    Root Administrator

    Default Re: More secure default settings - apache, php, ftp [Various Cases]

    Just as a FYI: While we plan to change the FTP defaults, we will also be reworking cPanel to resolve some known issues with the Anonymous FTP GUI (e.g. in some circumstances it may permit a user to seem to allow Anonymous FTP even if it has been disabled server-wide).

  8. #8
    Member
    Join Date
    Dec 2008
    Location
    Pune, India
    Posts
    31
    cPanel/WHM Access Level

    DataCenter Provider

    Default Re: More secure default settings - apache, php, ftp [Various Cases]

    It would be good to include all of CSF's security checklist so that admins don't need to waste 30 minutes after cPanel installation to change the defaults.
    CentralCP - Central cPanel/WHM Management - FREE
    LeapSwitch Networks - Managed VPS, Dedicated Servers & Colocation
    LaceHost Web Hosting Solutions

  9. #9
    Member
    Join Date
    Aug 2001
    Location
    Brisbane, Australia
    Posts
    247

    Default Re: More secure default settings - apache, php, ftp [Various Cases]

    +1 for this, anything to save time after all time is $$$

  10. #10
    Member
    Join Date
    Apr 2010
    Posts
    67

    Default Re: More secure default settings - apache, php, ftp [Various Cases]

    CSF would be a good starting point but there are some warnings in CSF that might break things, epecially php if set up the way CSF likes it to

Similar Threads

  1. Filed with Developers Apache HTTP Server 2.2.21 Released [Cases 53139, 53140]
    By Ivan A in forum Feature Requests for cPanel & WHM
    Replies: 3
    Last Post: 09-15-2011, 09:14 AM
  2. [Cases 52281, 51103] PHP 5.3.7 Released!
    By Ivan A in forum Archived Feature Requests
    Replies: 9
    Last Post: 08-28-2011, 09:53 AM
  3. cPanel Default Settings
    By cpanelgermain in forum cPanel & WHM Discussions
    Replies: 3
    Last Post: 07-27-2009, 10:57 AM
  4. htaccess - Default settings?
    By skuliaxe in forum New User Questions
    Replies: 1
    Last Post: 07-17-2009, 04:52 PM
  5. default 'new account' settings
    By wcn in forum cPanel & WHM Discussions
    Replies: 3
    Last Post: 11-04-2005, 04:39 AM

Tags for this Thread