Plain FTP transmits data without encryption, exposing credentials and files to interception. Learn why SFTP or FTPS should replace it entirely.
The Fundamental Problem With Plain FTP
Traditional FTP transmits usernames, passwords, and file contents in plain text over the network. Anyone able to intercept that traffic — on a shared network, compromised router, or through other interception techniques — can read credentials and data directly, with no decryption required.
SFTP vs. FTPS: The Secure Alternatives
- SFTP (SSH File Transfer Protocol) runs over an encrypted SSH connection, protecting both credentials and file contents in transit.
- FTPS (FTP Secure) adds SSL/TLS encryption to traditional FTP, achieving a similar security outcome through a different mechanism.
Either option is dramatically more secure than plain FTP, and most modern FTP clients support both.
How to Enable SFTP on a cPanel Server
SFTP is generally available by default wherever SSH access is enabled, since it uses the same underlying protocol and port. Ensure users connect using an SFTP-compatible client (like FileZilla or WinSCP) and select “SFTP” rather than “FTP” as the connection protocol, using port 22 (or your custom SSH port).
How to Enable FTPS in WHM
- In WHM, navigate to Service Configuration > FTP Server Configuration.
- Confirm your FTP server software (typically Pure-FTPd or ProFTPd) is configured to support TLS/SSL.
- Ensure a valid SSL certificate is installed and applied to the FTP service.
- Instruct users to select “FTPS” (Explicit or Implicit, as configured) in their FTP client settings.
Making the Transition
- Communicate the protocol change clearly to all users and update any saved connection profiles.
- Disable plain FTP entirely once all users have migrated, removing the insecure option altogether.
- Test file transfers after migration to confirm functionality before fully deprecating plain FTP.
Moving away from plain FTP is a straightforward change that eliminates an entire category of credential and data interception risk.