Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Protect Your Server From Brute Force Attacks

A brute force attack is when a bot guesses your passwords again and again. This guide shows simple ways to stop it. You need root access, so it fits VPS and dedicated server owners.

Dedicated Servers2 min read7 steps1 screenshots

What is a brute force attack?

Imagine a thief trying every key on a huge ring until one opens your door. A brute force attack works the same way. A program tries thousands of passwords on your login pages, such as SSH (the secure remote login to your server) or your control panel.

bute force attack, prevent brute force attack

Root is the main admin user on a server. It can change everything, so it is the top target.

Steps

  1. Log in to your server over SSH as root.
  2. Take a backup of the file you are about to change. For SSH, run the command below.
cp /etc/ssh/sshd_config /etc/ssh/sshd_config.bak

This makes a safe copy of the SSH settings file.

  1. Open the file with nano /etc/ssh/sshd_config.
  2. Find the line PermitRootLogin. Change it to PermitRootLogin no only after you have made another admin user who can log in. Otherwise you may lock yourself out.
  3. Find MaxAuthTries and set it to 3. The server will then cut off a visitor after three wrong tries.
  4. Optional: change the Port number to a different one. Bots mostly knock on the default port 22. Write down the new number first.
  5. Save the file. Restart SSH with the command below.
systemctl restart sshd

This reloads the SSH service with your new rules. Keep your current window open and test a new login in a second window.

Add a firewall that blocks bad guessers

A tool such as CSF with LFD or Fail2ban watches your logs. When one address fails to log in too many times, the tool blocks it for a while. Install one of them and keep it running. If you use a control panel, it may already include one. You can ask Hostvento support what suits your server.

Use strong passwords or SSH keys

An SSH key is a pair of long secret files that work like a very strong password. Once keys work, you can turn off password logins by setting PasswordAuthentication no. For other passwords, use a long mix of letters, numbers and symbols, and never reuse them.

Tip: Keep your server software updated. Updates close holes that attackers use.

Quick recap

  • Brute force means a bot guesses passwords many times.
  • Limit login tries and avoid direct root login.
  • Install CSF/LFD or Fail2ban to block repeat offenders.
  • Prefer SSH keys and strong passwords.
  • Back up config files and test in a second window before closing your first.