Arama Yap Mesaj Gönder
Biz Sizi Arayalım
+90
X
X
X
X

Knowledge Base

Homepage Knowledge Base What is the Apache mod_userdir Setting in WHM?...

Bize Ulaşın

Konum Halkalı merkez mahallesi fatih cd ozgur apt no 46 , Küçükçekmece , İstanbul , 34303 , TR

What is the Apache mod_userdir Setting in WHM? Its Importance in Terms of Security and a Guide to Correct Configuration

On cPanel & WHM servers, the Apache mod_userdir feature, which allows URL access in the format "http://siteadi.com/~user", although offering a practical use, is a feature that needs to be carefully configured in terms of performance and security.

In this article, we will discuss step by step what mod_userdir is, what it does, what risks it carries, and how to activate mod_userdir protection via WHM.


What is mod_userdir? What Does It Do?

When enabled on Apache servers, mod_userdir provides direct access to user directories in the form "http://domain.com/~username". This can be useful, especially for developers who want to temporarily access the site during the testing process.

For example:

http://ekasunucu.com/~mehmet  → goes to the /home/mehmet/public_html directory.

However, there is an important problem here: All traffic made in this way is reflected in the bandwidth quota of the main domain name, ekasunucu.com. This situation both prevents fair resource usage and is open to abuse in shared hosting environments.


⚠️ Why is mod_userdir Protection Necessary?

  1. Unfair traffic loading: Although the user seems to be accessing the ~mehmet directory, the bandwidth is reflected on ekasunucu.com.

  2. Security vulnerabilities: Some malicious users may try to view the content of other accounts using this feature.

  3. SSL incompatibility: ~user access is not compatible with SSL, HTTPS access errors occur.

  4. Server load: System resources cannot be used correctly, performance decreases.


Enabling mod_userdir Protection via WHM

  1. Log in to WHM as root.

  2. Open the Security CenterApache mod_userdir Tweak section from the left menu.

  3. Check the "Enable mod_userdir Protection" box at the top of the page.

  4. In the user list below, you can select the accounts that you will allow this access as an exception (usually left blank).

  5. Save the settings by pressing the Save button at the bottom of the page.

⚠️ Recommendation: On shared servers, it is recommended that you do not leave this feature open to any user.


What to Do If You Need to Use the mod_userdir Feature Temporarily?

  • If a domain has not been redirected yet, you can temporarily disable protection for access testing.

  • Be sure to reactivate it after the test is complete.

Alternatively:

  • The user can be allowed to test with a temporary URL. (For example, instead of http://ipadres/~user, a preview domain configured directly with the server IP can be used.)


In Summary

Although mod_userdir seems useful, it is not recommended to leave it directly active. Since it brings with it problems related to server quota, security and SSL, activating protection via WHM is the most accurate approach.

We also recommend that you take a look at the following for cPanel & WHM security:

     

Can't find the information you are looking for?

Create a Support Ticket
Did you find it useful?
(64274 times viewed / 30105 people found it helpful)

Call now to get more detailed information about our products and services.

Top