Disable Apache Configuration & DirectoryIndexing

MajorLancelot

Well-Known Member
Dec 17, 2014
74
5
133
Tokyo, Japan and Atlanta, Georgia
cPanel Access Level
Root Administrator
cPanel has over the years disabled by default WHM features that have become redundant.

This is good since it reduces attack surface even in misconfigured servers.

With cPanel File Manager, SSH, SFTP, Web Dav, etc, I was wondering why cPanel why the DirectoryIndex is still left enabled by default in Apache Configuration even with the obvious security implications and the fact that new users don't know much about adding Options -Indexes to .htaccess.

Even if directory mapping is still needed (can't think of one reason), isn't there a way cPanel can improve on this to make it safer for cPanel users?

Thanks!
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,880
2,270
463
Hello @MajorLancelot,

We consider security and usability when deciding on the default options enabled as part of new cPanel & WHM installations. When the Apache Indexes option is disabled, it's more likely users will encounter the "403 Forbidden" errors when attempting to access a domain name prior to uploading an index file.

I recommend opening a feature request to suggest disabling the Apache Indexes option by default.

Thank you.