Anonymous FTP access allows uncontrolled, unauthenticated file access on your server. Here’s why it should be disabled and how to do it properly.
What Anonymous FTP Access Means
Anonymous FTP allows anyone to connect to your FTP server without providing a username or password, typically intended for public file distribution in decades past. On a modern hosting server, this feature is rarely needed and represents a significant, often overlooked security gap.
Why It’s Dangerous
Anonymous FTP access can allow unauthenticated users to browse, and in misconfigured setups, even upload files to your server. Attackers actively scan for servers with anonymous FTP enabled, using them to host malicious files, phishing pages, or as a foothold for further compromise.
How to Check for Anonymous FTP in WHM
- Log in to WHM and navigate to Service Configuration > FTP Server Configuration.
- Look for an option related to “Anonymous FTP” or “Allow Anonymous Login” within your FTP server’s settings (Pure-FTPd or ProFTPd, depending on your setup).
- Confirm the setting is disabled; if enabled, switch it off immediately.
- Save the configuration and restart the FTP service to apply the change.
Verifying the Change
Attempt to connect to your server’s FTP service using “anonymous” as the username with a blank or email-style password. A properly secured server should reject this connection outright.
Additional Hardening Steps
- Remove any anonymous FTP home directories left over from a previous configuration.
- Combine this with the broader FTP restrictions and SFTP/FTPS migration covered earlier in this series.
- Include anonymous FTP status checks in your regular server security audit.
Disabling anonymous FTP access removes an unauthenticated entry point that has no place on a modern, security-conscious hosting server.