Anonymous FTP. Security Issues?

craigedmonds

Well-Known Member
Oct 29, 2007
115
1
68
Europe
cPanel Access Level
Root Administrator
Twitter
Is enabling Anonymous FTP in WHM for all cpanel users a security issue for the server itself?

Of course I understand that if the cpanel user enables anonymous uploads, this is a security issue for his account but not for the whole server right?
 

chirpy

Well-Known Member
Verifed Vendor
Jun 15, 2002
13,437
34
473
Go on, have a guess
Indeed. Anonymous FTP allows anyone to create files on the server without authentication. If a flaw is found in an FTP application (or any other app with access to the upload area) it then becomes much easier to exploit such flaws. For that reason you should only ever enable anonymous FTP if you really have a need for it and cannot provide the functionality any other way.
 

sparek-3

Well-Known Member
Aug 10, 2002
2,174
281
388
cPanel Access Level
Root Administrator
Since cPanel now allows you to set FTP user home directories outside of the public_html directory. I think it is a better idea to just set up an FTP account and give out the username and password to that FTP account to all interested parties.

Not the best idea to give just anyone the username and password, but still better than allowing unauthenticated access. Just be sure that the user's home directory is outside of the public_html folder (so they can't upload malicious scripts and then access them on the web through your account).