Skip to main content

Invalid Login when attempting to tether caused by cPHulk

Comments

5 comments

  • cPanelMichael
    Hello :) Accounts can be locked out by cPhulk, not just the individual IP addresses. You may want to consider using CSF instead of cPHulk, as CSF will not lock you out of "root" during a brute force attack. Thank you.
    0
  • davidpbj
    Thanks for the reply. I now disable cPHulk as required. Do you know what setting I messed with to cause cPHulk to become so sensitive? It's not like I'm trying to login multiple times; the 1st time I attempt to login I get the "Invalid Login" error. I'm not sure why the logs show a "brute force" attempt; cPHulk logs don't show any actual brute force attacks occurring against my server inside that time frame. Thanks.
    0
  • cPanelMichael
    cPhulk is configured via: "WHM Home " Security Center " cPHulk Brute Force Protection" It's likely one of the following options was triggered: Maximum Failures By Account Maximum Failures Per IP You can enable "Send notification when brute force user is detected" should you decide to utilize cPhulk in the future so an alert is sent when a brute force user is detected. Thank you.
    0
  • davidpbj
    Thanks, but I am familiar with how to configure cPhulk. My original question remains: What ELSE would I have to change for cPhulk to suddenly begin demonstrating this behavior. No changes were made to cPhulk itself but I did follow the CSF recommendations to "harden" the server. Something that I did there is what caused cPhulk to behave this way. Before that point in time, I could login fine via tethering. Plus, I get the "Invalid Login" immediately upon trying to login while tethered - I'm not given a chance to even come close to the Maximum Failures By Account/Per IP thresholds. Also, I'm not getting any notification from the server when I get the "Invalid Login"; and I know that the function does work because I'll still occasionally get a notification about somebody (from a non-blocked country) attempting to brute force an account.
    0
  • Infopro
    Not sure I understand this completely, but am wondering about this comment: But if I disable cPHulk, I have no issues and with Cookie IP Validation disabled, I can seamlessly transfer between wi-fi and tethering without having to re-authenticate.
    You're changing IP addresses when you do this, correct?
    0

Please sign in to leave a comment.