Skip to main content

turn off cpanel download feature

Comments

20 comments

  • Infopro
    Where does that URL work from, exactly?
    0
  • weeming21
    after login to cpanel frontend e.g xyz.com:2083/cpsess4618130495/download?skipencode=1&file=/home/user/public_html/index.php i only enable some mail only features, but user still able to download my source code through the url. i need to disable the "download?" api(maybe), please advise
    0
  • Infopro
    but user still able to download my source code through the url.

    How does a normal user login to your cPanel to do this?
    0
  • weeming21
    How does a normal user login to your cPanel to do this?

    they are not normal user they got their username and password to login cpanel hosting account, we only enable some mail feactures(accounts, forwarder and autoreposnders) for them but they can use the url to download all our source code we need to protect our php source code or else they can read our database password from source.
    0
  • Infopro
    after login to cpanel frontend e.g xyz.com:2083/cpsess4618130495/download?skipencode=1&file=/home/user/public_html/index.php

    This URL does not work for me. Are you sure its a proper example?
    0
  • weeming21
    xyz.com is your server url cpsess4618130495 is your security token index.php is the file in your public_html, u put a index.php into your public_html first
    0
  • Infopro
    Yep, I got all that. Doesn't work for me.
    0
  • weeming21
    did you login to cpanel account? i disabled all features, but still able to download file from the "download?" url cpanel 11.50 centos 7
    0
  • 24x7ss
    Hello, Do you want to disable it completely and want to allow it to specific users ?
    0
  • weeming21
    actually i want to disable it if "File Manager" feature is disabled but even i disabled all features, the function till work.. i tried at
    0
  • Infopro
    they got their username and password to login cpanel hosting account, we only enable some mail feactures(accounts, forwarder and autoreposnders) for them

    You shouldn't need to give an email user any access to cPanel for those features. Provided the user logs in using a full email address as the username then, domain.com/webmail/ is where they should be logging in.
    0
  • weeming21
    Ok, maybe you still don't understand our need. We are web developer, we host our client website in our server. We provide them a cPanel account, for them to manage their own domain email accounts. So we must block their files access privilege, or else they can get our website souce code.
    0
  • weeming21
    Hello, Do you want to disable it completely and want to allow it to specific users ?

    how to disable it completely?
    0
  • weeming21
    anyone know how to disable the download function in the cpanel? e.g.
    0
  • Tom Risager
    The URL in your last post doesn't work (port number missing), but otherwise you're right. I see the same on our server, on a cPanel account with all features disabled - no icons at all. Looks like removing a feature from cPanel just hides it, making it harder (but not impossible) to access. Which is probably sufficient in the majority of cases. An obvious fix would be to use a different server for email, but perhaps that isn't possible in your case.
    0
  • weeming21
    is it possible to override the cpanel control panel url? e.g.: override the url https://www.domain.tld:2083/cpsess1234567890/xyz?kkkkk in apache we can use .htaccess to rewrite to url but in cpanel, i put .htaccess inside the base directory but no luck please advise
    0
  • cPanelMichael
    Hello :) Could you elaborate further on why you need to redirect cPanel? You can review the "Redirection" options in "WHM >> Tweak Settings" if you prefer to redirect users to the hostname or SSL certificate name. Thank you.
    0
  • weeming21
    because i wan to disable the /download? function in cpanel
    0
  • cPanelMichael
    i already limit my cpanel customer to access "email only" features, but they can use the " download?skipencode=1&file=/home/user1/public_html/index.php" to download the source code.

    Please note that cPanel access is going to provide the user with access to the account via FTP or SFTP where the user can download any files associated with the account. That being said, feel free to open a support ticket using the link in my signature so we can take a closer look. You can post the ticket number here so we can update this thread with the outcome. Thank you.
    0
  • cPanelMichael
    Hello :) I've been unable to locate a support ticket for this issue. Were you able to open a support ticket or address the issue through another method? I look forward to your response. Thank you.
    0

Please sign in to leave a comment.