Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

cphulk - period - protection or detection ?

Discussion in 'Security' started by ottdev, Mar 11, 2018.

  1. ottdev

    ottdev Well-Known Member

    Oct 1, 2013
    Likes Received:
    Trophy Points:
    cPanel Access Level:
    Root Administrator
    Please clarify this contradiction:
    cPHulk Brute Force Protection - Version 70 Documentation - cPanel Documentation

    This sounds like it's a PROTECTION period (as labeled). i.e. how long the block will last.

    "failures...within the Brute Force Protection Period" <= Now it sounds like this is a DETECTION period instead.
    "cPHulk locks the account for one minute for each attempt that you allow" <= and the number of failures is also used as the PROTECTION blocking minutes.

    Which is it? if I set 15 and 25 in these 2 boxes, is it
    25 failures within 15 minutes locks the user account for 25 minutes
    25 failures within 15 minutes locks the user account for 15 minutes

    i.e. the top box is both detection and protection period
    or the top box is detection only and bottom is failures and protection period
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Apr 11, 2011
    Likes Received:
    Trophy Points:
    cPanel Access Level:
    Root Administrator

    Think of it in terms of "how many failed login attempts" are allowed in a specific "time frame". Let's say you use these settings:

    Brute Force Protection Period (in minutes) - 15
    Maximum Failures by Account
    - 25

    If 25 login failures occur for an account within a 15-minute window of time, then the account is locked. The number of minutes the account is locked corresponds to the Maximum Failures by Account setting. If it's set to 25, then the account is locked for 25 minutes.

    Thank you.

Share This Page