+254725682556 +254725052660 info@ziprof.co.ke
Client Area

Security

How to Enable Brute-Force Login Protection for Your Control Panel

Brute-force protection watches login attempts on your hosting control panel and automatically blocks an IP address once it has made too many failed tries in a short time. It is one of the simplest defenses against automated tools that try thousands of password guesses in a row, and it works quietly in the background without you having to do anything.

Both control panels ZIPROF uses include a built-in version of this feature. The name and where you find it differ by panel, so use the section below that matches yours.

In cPanel

cPanel's version of this tool is called cPHulk Brute Force Protection. It runs at the server level, so on shared hosting it is generally already active and protecting every account, including yours, without any setup required. If your account gives you access to it:

  1. Log in to your control panel.
  2. Look for cPHulk Brute Force Protection under the security tools section. On most shared hosting accounts this is managed by the server administrator and will not appear in your menu, since it applies globally rather than per account.
  3. If it is visible to you, review the Failed Login Threshold and IP Based Brute Force Protection Period settings to see how many failed attempts are allowed before a block, and how long that block lasts.

If you do not see this option at all, that is normal. It simply means the protection is already applied centrally on ZIPROF's servers and there is nothing further for you to configure.

In DirectAdmin

DirectAdmin's equivalent is usually labeled Login Protection or Brute Force Monitor. To check it:

  1. Log in to your control panel.
  2. Go to Login Protection (or Brute Force Monitor) if it appears in your menu.
  3. Review the list of blocked IP addresses and, if the setting is available to you, the number of failed attempts allowed before a block is triggered.

As with cPanel, this feature is normally managed at the server level, so most customers will not need to turn anything on themselves. It is already protecting your login page in the background.

If you ever get locked out after several failed login attempts of your own, for example after resetting a forgotten password and mistyping it a few times, wait a short while for the block to clear on its own, or contact ZIPROF support to have your IP address unblocked sooner.

Other ways to strengthen your login security

  • Use a long, unique password for your control panel account rather than one reused elsewhere.
  • Turn on two-factor authentication so a stolen password alone is not enough to log in.
  • Never share your control panel login details over email or chat, even with someone claiming to be support.

For a step-by-step guide to adding a second layer of login security, see How to Enable Two-Factor Authentication for Your Control Panel Login.