FTP service more secure by default
Completed
As a Server Administrator, I want the FTP service more secure by default, so that the overall security regarding the default settings for FTP is increased.
Currently the default setting for Anonymous FTP in Pure-FTPd allows anonymous logins. Changing this to disallow anonymous logins would aid in increasing initial server security.
We should disallow anonymous logins disallow anonymous uploads and disallow root logins via FTP by default.
- Allow Anonymous Logins = No
- Allow Anonymous Uploads = No
- Allow Logins with Root Password = No
This was shipped in v70 for new installs.
https://documentation.cpanel.net/display/70Docs/70+Release+Notes#id-70ReleaseNotes-AllowrootloginstoFTPoptiondefaultstoNoinnewinstallations
This was shipped in v70 for new installs.
https://documentation.cpanel.net/display/70Docs/70+Release+Notes#id-70ReleaseNotes-AllowrootloginstoFTPoptiondefaultstoNoinnewinstallations
I can see the features on the WHM side now? But i agree all three should be no by default.
I can see the features on the WHM side now? But i agree all three should be no by default.
It looks like the only option that isn't currently defaulted to 'no' is logins with the root password. I'll definitely see what we can do about getting that one adjusted as well!
It looks like the only option that isn't currently defaulted to 'no' is logins with the root password. I'll definitely see what we can do about getting that one adjusted as well!
This was shipped in v70 for new installs.
https://documentation.cpanel.net/display/70Docs/70+Release+Notes#id-70ReleaseNotes-AllowrootloginstoFTPoptiondefaultstoNoinnewinstallations
This was shipped in v70 for new installs.
https://documentation.cpanel.net/display/70Docs/70+Release+Notes#id-70ReleaseNotes-AllowrootloginstoFTPoptiondefaultstoNoinnewinstallations
Replies have been locked on this page!