<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>security on</title><link>https://docs.whmcs.com/9-1/tags/security/</link><description>Recent content in security on</description><generator>Hugo -- gohugo.io</generator><atom:link href="https://docs.whmcs.com/9-1/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Enhancing Security</title><link>https://docs.whmcs.com/9-1/installation-guide/initial-configuration/enhancing-security/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/installation-guide/initial-configuration/enhancing-security/</guid><description>Enumerates ten security hardening steps for self-hosted installations: securing writeable directories, configuration.php, and crons, restricting Admin Area access by IP, renaming the admin directory, enabling SSL, and restricting database privileges.</description></item><item><title>Secure Writeable Directories</title><link>https://docs.whmcs.com/9-1/installation-guide/initial-configuration/secure-writeable-directories/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/installation-guide/initial-configuration/secure-writeable-directories/</guid><description>Walks through moving the attachments, downloads, and templates_c directories to a private location, updating the $templates_compiledir variable in configuration.php, and reconfiguring local storage paths in WHMCS&amp;rsquo;s Storage Settings interface using Switch or Migrate.</description></item><item><title>Security Questions</title><link>https://docs.whmcs.com/9-1/clients/security-questions/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/clients/security-questions/</guid><description>Covers adding and disabling security questions at Configuration &amp;gt; System Settings &amp;gt; Security Questions, users setting up or updating their question and answer under Hello, Name! &amp;gt; Security Settings in the Client Area, and admins removing a user&amp;rsquo;s question via Manage User&amp;rsquo;s Disable Security Question setting.</description></item><item><title>Spam Orders</title><link>https://docs.whmcs.com/9-1/orders/spam-orders/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/orders/spam-orders/</guid><description>Lists methods to reduce spam orders: third-party firewalls, reCAPTCHA v3 or hCaptcha, banning email domains, disabling client registration and presales forms, a custom human-verification client field, MaxMind&amp;rsquo;s automatic fraud detection, and Only Auto Provision for Existing.</description></item><item><title>API Credentials</title><link>https://docs.whmcs.com/9-1/system/authentication/api-credentials/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/api-credentials/</guid><description>Details the steps to create, edit, and delete API roles and API credential pairs at Configuration &amp;gt; System Settings &amp;gt; Manage API Credentials, including generating identifier/secret pairs and assigning permission roles to a credential.</description></item><item><title>Client Email Verification</title><link>https://docs.whmcs.com/9-1/clients/client-email-verification/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/clients/client-email-verification/</guid><description>Explains how to enable email verification in the Security tab of General Settings, when verification emails trigger (new registration or email address change), the 60-minute validity of verification links, how users resend expired links, and where admins view verification status on the client Summary tab.</description></item><item><title>Secure the Configuration File</title><link>https://docs.whmcs.com/9-1/installation-guide/initial-configuration/secure-the-configuration-file/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/installation-guide/initial-configuration/secure-the-configuration-file/</guid><description>Gives the chmod command to set configuration.php permissions to 400, lists fallback permissions (440, 444) for errors loading WHMCS, and notes the temporary 755 permission needed to update the license key.</description></item><item><title>Move the Cron Directory</title><link>https://docs.whmcs.com/9-1/installation-guide/initial-configuration/move-the-cron-directory/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/installation-guide/initial-configuration/move-the-cron-directory/</guid><description>Walks through moving the crons directory above the web root, updating cron tasks and email forwarders, editing the crons config.php and configuration.php files with the new path, and updating the system cron command in cPanel.</description></item><item><title>Rename the Admin Directory</title><link>https://docs.whmcs.com/9-1/installation-guide/initial-configuration/rename-the-admin-directory/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/installation-guide/initial-configuration/rename-the-admin-directory/</guid><description>Walks through adding the $customadminpath variable to configuration.php, renaming the admin directory to match it, and re-uploading files to the custom directory name after applying WHMCS updates or patches.</description></item><item><title>Banned IP Addresses</title><link>https://docs.whmcs.com/9-1/system/banned-ip-addresses/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/banned-ip-addresses/</guid><description>Covers manually adding, searching, filtering, and deleting entries on the Banned IPs list with wildcard IP ranges, the three-failed-login automatic ban trigger, removing an automatic ban via the tblbannedips database table, and restricting Admin Area access with an .htaccess allow-list.</description></item><item><title>Captcha Protection</title><link>https://docs.whmcs.com/9-1/system/captcha-protection/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/captcha-protection/</guid><description>Compares the verification-code, checkbox (reCAPTCHA v2/hCaptcha), and invisible (reCAPTCHA v3/Invisible hCaptcha) captcha types, and gives the steps to select a Captcha Type, enter the Site Key and Secret Key, and set a score threshold under General Settings &amp;gt; Security.</description></item><item><title>Cron HTTP Access Denied Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-cron-issues/cron-http-access-denied-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-cron-issues/cron-http-access-denied-errors/</guid><description>Covers the 403 Access Denied error returned by crons/cron.php or the legacy admin/cron.php alias when a direct HTTP request&amp;rsquo;s IP address is not on the Cron HTTP Access Restriction allowlist, and gives the fix of invoking cron via CLI or adding the caller&amp;rsquo;s IP address or CIDR range to the allowlist in General Settings&amp;rsquo; Security tab.</description></item><item><title>Enable Default Captchas</title><link>https://docs.whmcs.com/9-1/system/system-tutorials/enable-default-captchas/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/system-tutorials/enable-default-captchas/</guid><description>Gives the steps to select Default (6 Character Verification Code) for Captcha Type and choose locations under Captcha for Select Forms on the Security tab of General Settings, noting the GD2 server requirement.</description></item><item><title>Enable hCaptcha®</title><link>https://docs.whmcs.com/9-1/system/system-tutorials/enable-hcaptcha/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/system-tutorials/enable-hcaptcha/</guid><description>Steps through selecting hCaptcha or Invisible hCaptcha for Captcha Type, authorizing the WHMCS domain in the hCaptcha account, entering the Site Key and Secret Key, setting the hCaptcha Score Threshold, and choosing Captcha for Select Forms locations on the Security tab of General Settings.</description></item><item><title>Enable reCAPTCHA v3</title><link>https://docs.whmcs.com/9-1/system/system-tutorials/enable-recaptcha-v3/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/system-tutorials/enable-recaptcha-v3/</guid><description>Steps through selecting reCAPTCHA v3 for Captcha Type, registering a Score based (v3) site in the Google reCAPTCHA admin console, entering the Site Key and Secret Key, setting the reCAPTCHA Score Threshold, and choosing Captcha for Select Forms locations on the Security tab of General Settings.</description></item><item><title>Grant Access to WHMCS Support</title><link>https://docs.whmcs.com/9-1/troubleshooting/grant-access-to-whmcs-support/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/grant-access-to-whmcs-support/</guid><description>Lists the WHMCS Support IP addresses and ranges to allowlist, the steps to create a temporary full-administrator user, cPanel and Plesk SSH key setup script commands, and the steps to remove temporary access and the admin user once support finishes.</description></item><item><title>Security</title><link>https://docs.whmcs.com/9-1/system/general-settings/general-settings-security/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/general-settings/general-settings-security/</guid><description>Documents Email Verification, Captcha Form Protection and Captcha Type options (Default, reCAPTCHA v2/v3, hCaptcha) with their Site/Secret Key and score threshold fields, Auto Generated Password Format, Minimum Password Length and Password Reuse Limit (with their PCI DSS-mandated lower limits of 12 and 4), Minimum User Password Strength, Failed Admin Login Ban Time, Whitelisted IPs, Trusted Proxies, Proxy IP Header, API IP Access Restriction, CSRF Token settings, and the Cron HTTP Access Restriction allowlist that gates direct HTTP requests to crons/cron.php.</description></item><item><title>Sensitive Directory Check Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/general-troubleshooting/sensitive-directory-check-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/general-troubleshooting/sensitive-directory-check-errors/</guid><description>Resolves the System Health &amp;ldquo;Sensitive Directory Check&amp;rdquo; messages: a sensitive directory such as /vendor is web-accessible, a configured Storage Settings location (for example, Ticket Attachments, Client Files, or Downloads) is web-accessible, WHMCS could not determine whether a directory is web-accessible, or the System URL setting is not configured. Provides fixes per server type for exposed directories (verifying .htaccess exists and AllowOverride is not None on Apache, enabling .htaccess on OpenLiteSpeed, or manually restricting access on other servers like NGINX), moving or protecting an exposed Storage Settings location, configuring the System URL, and resolving directories that could not be evaluated.</description></item><item><title>Administrator Password Refused Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-installation/administrator-password-refused-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-installation/administrator-password-refused-errors/</guid><description>Covers the web and CLI installer&amp;rsquo;s initial-admin password refusal: the 12-64 character, 72-byte, letter, number, and UTF-8 rules, the HTML-encoded-length edge case, and the CLI&amp;rsquo;s stdout-only, unlogged message with a non-zero exit status.</description></item><item><title>Enable Encrypted MySQL</title><link>https://docs.whmcs.com/9-1/system/database-and-storage/database-and-storage-tutorials/encrypt-your-mysql-connection/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/database-and-storage/database-and-storage-tutorials/encrypt-your-mysql-connection/</guid><description>Lists the db_tls_ca, db_tls_ca_path, db_tls_cert, db_tls_cipher, db_tls_key, and db_tls_verify_cert configuration.php settings needed to enable encrypted MySQL connections before, during (CLI -c/&amp;ndash;config), or after installation.</description></item><item><title>Restrict NGINX Directory Access</title><link>https://docs.whmcs.com/9-1/installation-guide/initial-configuration/restrict-nginx-directory-access/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/installation-guide/initial-configuration/restrict-nginx-directory-access/</guid><description>Details protecting the /vendor/ directory on NGINX servers that don&amp;rsquo;t read .htaccess, using cPanel &amp;amp; WHM&amp;rsquo;s Directory Privacy interface (v84+) or manual NGINX deny directives, plus locating the NGINX config file and restart commands by server type.</description></item></channel></rss>