The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Disable TRACE Method on Cpanel 11.30.6 (build 3)

Discussion in 'Security' started by manishbathla, Mar 23, 2012.

  1. manishbathla

    manishbathla Member

    Joined:
    Mar 23, 2012
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    1
    cPanel Access Level:
    Website Owner
    Hello,

    How do I disable TRACE Method on Cpanel 11.30.6 (build 3), Apache version 2.2.22?.
    Id appreciate if you guys help me regarding this.

    Manish.
     
  2. JeffP.

    JeffP. Well-Known Member

    Joined:
    Sep 28, 2010
    Messages:
    164
    Likes Received:
    10
    Trophy Points:
    18
    Hi Manish,

    Try this please:

    WHM >> Apache Configuration >> Global Configuration >> Trace Enable (set to Off) >> Save >> Rebuild Configuration and Restart Apache.

    That should do the trick.
     
  3. manishbathla

    manishbathla Member

    Joined:
    Mar 23, 2012
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    1
    cPanel Access Level:
    Website Owner
    Hello Jeff,

    I had a chat with the company i bought the space from. They say in order to access WHM, I need to buy the reseller package which cost 10x more than what I have already paid for.

    Is there a way to disable the TRACE method via cpanel?. Sorry, I do not know much about cpanel or WHM as am new here but I hope there is a way to disable the TRACE method in order to secure my website.

    Thanks for responding Jeff.
     
  4. NixTree

    NixTree Well-Known Member

    Joined:
    Aug 19, 2010
    Messages:
    387
    Likes Received:
    1
    Trophy Points:
    18
    Location:
    Gods Own Country
    cPanel Access Level:
    Root Administrator
    Hello,

    No, you cannot disable TraceEnable globally without root access. If you would like to disbale this for your website, put something like below in your htaccess file

    RewriteEngine On
    RewriteCond %{REQUEST_METHOD} ^TRACE
    RewriteRule .* - [F]

    Or ask your host to disable it globally, since it is recommended to set off by default.

    Thank you,
    Nibin.
     
  5. manishbathla

    manishbathla Member

    Joined:
    Mar 23, 2012
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    1
    cPanel Access Level:
    Website Owner
    Thank you Nibin for the suggestion. I'll put that in my .htacess file and ask the service provider to disable it globally.
     
Loading...

Share This Page