How to use Leech Protection in Linux cPanel ?
When users publicly post their username and password, unauthorized visitors can use their credentials to access secure areas of your web site. After you set the maximum number of logins within a two-hour period, the system redirects or suspends users who exceed it. This is useful if, for example, someone posts a user’s login credentials protection on a public site.
This also prevents a user who is trying to access another’s account using the correct username and trying to login using multiple combinations of passwords by guessing them. This prevents users from logging in multiple times within a short time span.
Please follow the below procedure to setup leech protect for a domain name
[1] Login to cPanel
[2] Click on Security tab
[3] Click on Leech protection
[4] You will get a new windows where you can select a particular folder which you wish to protect.
[5] Once you click on a particular directory, you will get a new window where you can set the required permissions.
[6] Enter the maximum number of logins that you wish to allow each user within a two-hour period.
[7] To redirect users who exceed the maximum number of logins within a two-hour period, enter a URL to which you wish to redirect them.
[8] To configure the system to send an email alert when Leech Protection activates, select the Send Email Alert To checkbox. Then, enter the email address to alert.
[9] To disable an account that exceeds the maximum number of logins, select the Disable Compromised Accounts checkbox.
[10] Click Enable.
To add, edit, and delete users, perform the following steps:
[1] Navigate to a directory that you wish to protect with user-level protection.
[2] Click Manage Users to navigate to cPanel’s Directory Privacy interface for that folder (cPanel >> Home >> Security >> Directory Privacy).
Note : To manage users manually, edit the /home/USERNAME/.htpasswds/public_html/passwd file, where USERNAME represents the account name.
To disable leech protection, perform the following steps:
[1] Navigate to the directory for which you wish to disable leech protection.
[2] Click Disable.