Knowledgebase

Brute-Force Attacks and How to Stop Them Print

  • securityabuse, security, bruteforce, password, cpanel, resourcelimits, php, ftp, firewall, twofactor
  • 0

Brute forcing means trying password after password against a login page. Bots do this against every website on the internet continuously.

WHY IT MATTERS EVEN WHEN IT FAILS

Each attempt is a full request that consumes your CPU and entry process allowance. Sites are frequently slowed to a crawl by attacks that never succeed.

SERVER-SIDE PROTECTION

Our firewall detects repeated failed logins to cPanel, FTP and mail, and blocks the source address automatically. This is also why you may block yourself after several mistyped passwords.

WHAT YOU SHOULD ADD

Limit login attempts within your application, with lockouts after a few failures. Enable two-factor authentication on all administrator accounts. Change the default login URL where your platform allows it. Use cPanel Directory Privacy in front of the admin folder so bots never reach the application. Block xmlrpc.php if you do not use it, as it allows many password attempts in a single request. Use a Cloudflare rate-limiting or challenge rule on the login path.

IF YOU ARE LOCKED OUT YOURSELF

Open a ticket from the Client Area with your current IP address from whatismyip.com and we will release it.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot