Knowledgebase

Using Leech Protection on Password-Protected Areas Print

  • cpanel, password, plugins, suspension, wordpress, email, security, hacked, ipaddress, redirects
  • 0

Leech protection detects when one login is being shared widely, which typically means a member has published their credentials.

HOW IT WORKS

It watches a password-protected directory and counts logins from distinct locations within a two-hour window. When the count exceeds your threshold, it suspends the account.

SETTING IT UP

  1. Protect a directory first using Directory Privacy.
  2. In cPanel open Leech Protection under Security.
  3. Browse to the directory and click it.
  4. Set "Number of logins allowed in a 2-hour period". Between 3 and 5 suits most cases.
  5. Optionally set a redirect URL for disabled users.
  6. Tick "Send email alert to" and enter your address.
  7. Optionally tick "Disable compromised accounts" to suspend automatically.
  8. Click Enable.

LIMITATIONS

This only applies to directories protected with cPanel Directory Privacy. It does not monitor WordPress logins or a membership plugin. For those, use the sharing controls in the membership plugin itself.

Legitimate users on mobile networks change IP address often and can trigger it, so do not set the threshold too low.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot