Skip to main content

cphulk - period - protection or detection ?

Comments

10 comments

  • cPanelMichael
    Hello, Think of it in terms of "how many failed login attempts" are allowed in a specific "time frame". Let's say you use these settings: Brute Force Protection Period (in minutes) - 15 Maximum Failures by Account - 25 If 25 login failures occur for an account within a 15-minute window of time, then the account is locked. The number of minutes the account is locked corresponds to the Maximum Failures by Account setting. If it's set to 25, then the account is locked for 25 minutes. Thank you.
    0
  • ottdev
    Thank you. so this statement in the docs in indeed INCORRECT: "Brute Force Protection Period (in minutes): The number of minutes for which cPHulk blocks all login attempts on a specific user's account"
    0
  • cPanelMichael
    Thank you. so this statement in the docs in indeed INCORRECT: "Brute Force Protection Period (in minutes): The number of minutes for which cPHulk blocks all login attempts on a specific user's account"

    I've opened a case with our Documentation Team (DOC-10557) to have the description of this option updated. I'll update this thread once the change is published. Thank you.
    0
  • cPanelMichael
    Hello, The document is now updated with a more accurate description: cPHulk Brute Force Protection - Version 70 Documentation - cPanel Documentation Thanks!
    0
  • ottdev
    That is clear now. Thank you :) HOWEVER ... Further down the page you have the same incorrect? I suspect OLD verbiage for the other field. I assume they both work the same way? IP Address-based Brute Force Protection Period (in minutes) The number of minutes during which cPHulk blocks an attacker's IP address.
    0
  • cPanelMichael
    Hello @ottdev, I've opened internal case DOC-10624 for that particular part of the document. I'll update this thread again once the case is complete. Thank you.
    0
  • cPanelMichael
    Hello, The changes are now published. Thanks!
    0
  • Zardiw
    Be nice if there was an explanation of the advantages of values in these fields. .....Also, they should be split into 2 fields. i.e. The detection period, and the block period. And the ability to permanently add IP's blocked to the firewall....i.e. IPTables. How does values in the detection period affect protection?....i.e. What is the practical difference between having a short vs long detection period? Z
    0
  • cPRex Jurassic Moderator
    @Zardiw - this thread is a few years old and the old documentation links are likely no longer accurate. Can you make a new post if you're seeing issues with the documentation so I can check that out?
    0
  • Zardiw
    Thank you for the response.......I have started a new thread:
    0

Please sign in to leave a comment.