How to turn off index viewing by default in EA?

dwh2

Well-Known Member
Jan 14, 2004
106
0
166
I don't want people to be able to surf directories by default if there's no index.html file in a directory. I thought I set that up somewhere in WHM, but I guess not.

I notice that EA3 builds Apache with this directive:

Code:
<Directory "/usr/local/apache/htdocs">
    Options Indexes FollowSymLinks
    AllowOverride None
    Order allow,deny
    Allow from all

</Directory>
If I want it turned off, do I just remove "Indexes" above and run that cpanel program to register the change? Or is it somewhere else?

Also, may I add a feature request that you add this option into the EA3 builder so we can turn indexes on/off in the httpd.conf by default and let the users override our serverwide default... For security I think directory browsing off would be better.

P.S. a similar suggestion would be not to default ServerTokens FULL as default...although I changed it to Prod and checked in a server headers tool and it's still showing my PHP version for some reason...
 

dwh2

Well-Known Member
Jan 14, 2004
106
0
166
OK, how about the reverse...turning it off by default serverwide? That's what I was looking for.
 

jayh38

Well-Known Member
Mar 3, 2006
1,212
0
166
in the servers /home create a .htaccess with the following:

Options All -Indexes
 

dwh2

Well-Known Member
Jan 14, 2004
106
0
166
Thanks...so just /home/.htaccess and it will propagate to the directories below it?

Wow, cool.
 

jamesbond

Well-Known Member
Oct 9, 2002
737
1
168
If you enable index viewing by default, why not give people the option to turn off index viewing when compiling apache?

Don't most hosts/server owners have indexing turned off for security reasons? Why enable it server wide by default if generally only a handful of users on a server might actually be interested in it. IMO it makes more sense to disable it by default and have the few users that need it enable it in their own cpanel account.
 

cPanelDavidG

Technical Product Specialist
Nov 29, 2006
11,212
13
313
Houston, TX
cPanel Access Level
Root Administrator
If you enable index viewing by default, why not give people the option to turn off index viewing when compiling apache?

Don't most hosts/server owners have indexing turned off for security reasons? Why enable it server wide by default if generally only a handful of users on a server might actually be interested in it. IMO it makes more sense to disable it by default and have the few users that need it enable it in their own cpanel account.
That sounds like a good idea for an official feature request. You can submit official feature requests to http://bugzilla.cpanel.net
 

cesare

Registered
Mar 16, 2006
4
0
151
in the servers /home create a .htaccess with the following:

Options All -Indexes
Im fairly new to this, but I have the understanding that using .htaccess files will create a recursive search through the subdirectories.
Could someone more knowledgeable please elaborate on the consequences, compared to using a directive instead?