Knowledgebase

Protecting Against Brute-Force Attacks Print

  • vpsservermanagement, bruteforce, password, firewall, database, ftp, twofactor, troubleshooting
  • 0

Automated password guessing against every exposed service.

WHAT IS TARGETED

SSH, control panel logins, FTP, mail, database ports, and application login pages.

THE PRIMARY DEFENCE

Remove passwords where you can. SSH key authentication cannot be brute-forced.

For services where passwords are unavoidable, use long unique ones.

AUTOMATED BLOCKING

fail2ban monitors logs and blocks addresses after repeated failures. CSF provides similar functionality alongside its firewall.

Configure it for SSH at minimum, and for your control panel, mail and application logins if supported.

Set thresholds that block attackers without locking out legitimate users who mistype twice.

RESTRICTING BY SOURCE

If you administer from a fixed address, restrict SSH and control panel access to it in the firewall. This is the strongest control available and costs nothing.

WHAT ELSE HELPS

Changing default ports, which removes most automated noise Two-factor authentication on control panel access Disabling services you do not use

MONITORING

Check how many attempts you are seeing. A sudden increase can precede a more targeted attempt.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot