Difference between revisions of "Further Security Steps"

From WHMCS Documentation

(New page: The guide below describes various extra steps you can take to furthur secure your WHMCS system. ==Move the attachments, downloads & templates_c folders== The three folders "attachments",...)
 
Line 5: Line 5:
 
The three folders "attachments", "downloads" and "templates_c" need to be writeable by WHMCS and therefore require the permissions 777 (writeable by all).  When folders have this permission level it is safer to place the folders outside of the public accessible folder tree on your website.  WHMCS allows you to do this.  If you do move the folders, then you must tell WHMCS where they have been moved to by adding the following lines to your configuration.php file:
 
The three folders "attachments", "downloads" and "templates_c" need to be writeable by WHMCS and therefore require the permissions 777 (writeable by all).  When folders have this permission level it is safer to place the folders outside of the public accessible folder tree on your website.  WHMCS allows you to do this.  If you do move the folders, then you must tell WHMCS where they have been moved to by adding the following lines to your configuration.php file:
  
$templates_compiledir = "/home/whmcs/templates_c/";<br />
+
$templates_compiledir = "/home/whmcs/templates_c/";
$attachments_dir = "/home/whmcs/attachments/";<br />
+
$attachments_dir = "/home/whmcs/attachments/";
$downloads_dir = "/home/whmcs/downloads/";<br />
+
$downloads_dir = "/home/whmcs/downloads/";
  
 
==Change your WHMCS Admin Folder name==
 
==Change your WHMCS Admin Folder name==
Line 13: Line 13:
 
Malicious users who visit your site and recognise a WHMCS install will know that they can try logging into your admin area via the admin folder.  To protect against this, you can rename the admin folder name to any name you like.  You cannot move the folder - only rename it.  You can then tell WHMCS what the name of that folder is for the links in admin notification emails by adding the following line to your configuration.php file:<br />
 
Malicious users who visit your site and recognise a WHMCS install will know that they can try logging into your admin area via the admin folder.  To protect against this, you can rename the admin folder name to any name you like.  You cannot move the folder - only rename it.  You can then tell WHMCS what the name of that folder is for the links in admin notification emails by adding the following line to your configuration.php file:<br />
  
$customadminpath = "myadminname";
+
$customadminpath = "myadminname";
 +
 
  
<br />
 
 
[[Installation|<< Back to Installation Overview]]
 
[[Installation|<< Back to Installation Overview]]

Revision as of 10:16, 20 March 2008

The guide below describes various extra steps you can take to furthur secure your WHMCS system.

Move the attachments, downloads & templates_c folders

The three folders "attachments", "downloads" and "templates_c" need to be writeable by WHMCS and therefore require the permissions 777 (writeable by all). When folders have this permission level it is safer to place the folders outside of the public accessible folder tree on your website. WHMCS allows you to do this. If you do move the folders, then you must tell WHMCS where they have been moved to by adding the following lines to your configuration.php file:

$templates_compiledir = "/home/whmcs/templates_c/";
$attachments_dir = "/home/whmcs/attachments/";
$downloads_dir = "/home/whmcs/downloads/";

Change your WHMCS Admin Folder name

Malicious users who visit your site and recognise a WHMCS install will know that they can try logging into your admin area via the admin folder. To protect against this, you can rename the admin folder name to any name you like. You cannot move the folder - only rename it. You can then tell WHMCS what the name of that folder is for the links in admin notification emails by adding the following line to your configuration.php file:

$customadminpath = "myadminname";


<< Back to Installation Overview