Skip to main content

cPHulk reports many failed login attempts

Comments

5 comments

  • cowboymike
    I should have noted in the post above that I do have ssh disabled and still get a ton of the failed login attempts notices. Thanks, Mike
    0
  • ravi9
    You can block those IP range in CSF firewall or in cPHulk. Like to block 111.111.xxx.xxx add following: 111.111.0.0/16
    Blocking in CSF firewall will completely block access from those IPs. Blocking in cPULK will only deny login in cPanel / Webmail
    0
  • cowboymike
    Thank you ravi9. But for as many failed login attempts I am getting it seems like it could be a full time job blocking IPs. The number of attempts is coming from a wide range of IPs with most from China, but I do get a lot from other countries and the US is probably next after china in terms of volume. I was blocking individual IPs in cPHulk but then someone wrote that that was an effort in futility because I could be blocking good IPs due something like IP spoofing or dynamic Ips or something. I dont recall exactly. I am not knowledgeable at this and I just want my couple of websites to be ok. So do you still think I am just going to have to put in the time and block IP ranges? Thank you. Mike
    0
  • cPanelMichael
    Hello :) cPhulk will not block IP addresses from making authentication "attempts". Instead, it prevents successful authentication. A firewall such as CSF is required to block IP addresses and prevent these types of attacks. You may want to post on the CSF forums if you would like advice on specific configuration values to enable/change in the CSF software: ConfigServer - Forums Thank you.
    0
  • ravi9
    [quote="cowboymike, post: 1498821">Thank you ravi9. But for as many failed login attempts I am getting it seems like it could be a full time job blocking IPs. The number of attempts is coming from a wide range of IPs with most from China, but I do get a lot from other countries and the US is probably next after china in terms of volume. Mike
    This is a common problem when you have few good traffic website on your server. Do not block many IPs, instead block few IP range. Install CSF firewall (if you do't have) Start bloking IP range. Like if you receive mail saying [QUOTE] Large Number of Failed Login Attempts from IP 61.147.70.?209
    Block 61.147.0.0/16 in CSF firewall. You will soon get 60-70% less failed login attempts mails.
    0

Please sign in to leave a comment.