Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

cPHulk Brute Force Protection Confusion

Discussion in 'Security' started by danielpmc, Nov 8, 2016.

Tags:
  1. danielpmc

    danielpmc Well-Known Member

    Joined:
    Nov 3, 2016
    Messages:
    64
    Likes Received:
    30
    Trophy Points:
    18
    Location:
    Gainesville, Florida
    cPanel Access Level:
    Reseller Owner
    Hello,

    On the page link below i found the following statement:

    Notes:
    cPHulk does not consider multiple login attempts that use the same IP address, username, and password to be separate failures if they occur within the same six-hour period.

    last modified by Doc User on Oct 10, 2016
    Code:
    https://documentation.cpanel.net/display/ALD/cPHulk Brute Force Protection
    Is this literally saying that nothing matters during the first 6 hours of any action taking place and cPHULK will not block any IP or User during the first 6 hours?

    Thanks.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    43,672
    Likes Received:
    1,788
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Hello,

    Another way of stating the behavior is that only one failure is recorded per six-hour period if the IP address, username, and password are all the same in each authentication attempt. For example, let's say a user with IP address 1.2.3.4 attempts to login to cPanel with the username "example123" and the password "password123" several times in a six-hour period. In this scenario, it's only counted as one failure. However, if a user with that same IP address then attempted to login with the username "example123" and the password "password12345678" in that same six-hour window, then that would count as an additional failure.

    Thank you.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
    PrashantG and danielpmc like this.
  3. danielpmc

    danielpmc Well-Known Member

    Joined:
    Nov 3, 2016
    Messages:
    64
    Likes Received:
    30
    Trophy Points:
    18
    Location:
    Gainesville, Florida
    cPanel Access Level:
    Reseller Owner
    Thanks cPanel Michael,

    I understand your explanation. Now i have a grasp on how to set the limits within cPHulk. Much appreciated. Consider this resolved.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
    cPanelMichael likes this.
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice