Protecting Admin Areas Print

  • otherapplicationsscripts, other, password, cpanel, email, twofactor, cloudflare, webhosting
  • 0

The page attacked most on any site.

WHY IT MATTERS

Login pages are attacked continuously by automated tools. Each attempt consumes your resources even when it fails.

THE LAYERS

  1. Strong unique passwords, and no username of admin or administrator.
  2. Two-factor authentication on every administrative account.
  3. Login attempt limiting, with lockouts after repeated failures.
  4. A changed login URL, which stops most untargeted bots outright.
  5. cPanel Directory Privacy in front of the admin directory, which stops them before the application runs.
  6. Cloudflare rules challenging or rate-limiting requests to the login path.

DIRECTORY PRIVACY

The strongest of these on shared hosting. It adds a server-level password prompt, so bots never reach your application at all. It also removes the resource cost of the attacks.

Note it adds a second login for legitimate users, which is a minor inconvenience for a significant gain.

WATCH FOR

Login notifications from unfamiliar locations Password reset emails you did not request Settings changing without explanation

All three are early warnings.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot