{"id":18362,"date":"2026-09-29T21:06:28","date_gmt":"2026-09-29T18:06:28","guid":{"rendered":"https:\/\/www.hyyat.com\/knowledgebase\/brute-force-protection\/"},"modified":"2026-09-29T21:06:28","modified_gmt":"2026-09-29T18:06:28","password":"","slug":"brute-force-protection","status":"publish","type":"docs","link":"https:\/\/www.hyyat.com\/en\/knowledgebase\/brute-force-protection\/","title":{"rendered":"Brute Force Protection: What It Is and How Hyyat Host Protects Your Site"},"content":{"rendered":"<div class=\"hy-tldr\" style=\"background:#f6f7fb;border-left:4px solid #d83954;border-radius:10px;padding:14px 18px;margin:0 0 20px;line-height:1.8\"><strong>In short:<\/strong> A brute force attack tries thousands of passwords automatically against WordPress, SSH, FTP or email logins. Hyyat Host servers record failed logins and block an IP address that keeps failing. If you are blocked by mistake after forgetting your password, you will see a CAPTCHA to unblock yourself.<\/div>\n<p>Brute force is one of the most common methods attackers use to get into a server. It is used against many targets:<\/p>\n<ul>\n<li>SSH<\/li>\n<li>FTP<\/li>\n<li>Email accounts<\/li>\n<li>CMS logins such as WordPress and Joomla<\/li>\n<\/ul>\n<p>Recently there has been a big increase in brute force attacks against WordPress and Joomla sites. They come from large networks of infected servers, so an attacker can test thousands of passwords per minute against one site.<\/p>\n<p>During an attack, the server load, memory use and CPU use all rise. On servers with limited memory the system can start swapping and fail, and the web server may hang until the server is restarted. Once attackers get into a WordPress or Joomla admin area, it is easy for them to upload malware, phishing pages or spam mailers.<\/p>\n<h2>How the protection works<\/h2>\n<p>Every time a login fails, the server records the IP address. If repeated failed logins come from the same IP, that IP is blocked from all login forms on the server, and the attacker only sees an &#8220;Access denied&#8221; message.<\/p>\n<p>The result: later login attempts from that IP never reach WordPress, which protects the server&#8217;s load, memory and CPU. The server stays stable during brute force attacks.<\/p>\n<h2>Blocked by mistake?<\/h2>\n<p>Sometimes it is not an attack: a real user forgets their password and triggers the protection. In this case, instead of &#8220;Access denied&#8221;, you will see a CAPTCHA test. Solve it and your IP address is unblocked and the login form appears again.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.hyyat.com\/zasogooh\/2019\/01\/bf-captcha.png\" alt=\"Brute force protection CAPTCHA\" \/><\/p>\n<p>To stay safe, use long, unique passwords and enable two-factor authentication where possible. See also how to protect your website from hacking.<\/p>\n<p class=\"hy-svc-link\" style=\"background:#fff5f7;border-left:4px solid #d83954;border-radius:10px;padding:14px 18px;margin:20px 0;line-height:1.8\"><strong>Related service:<\/strong> <a href=\"https:\/\/www.hyyat.com\/en\/wordpress-hosting\/\">Hyyat Host WordPress hosting<\/a> includes brute force protection, free SSL and 24\/7 support.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In short: A brute force attack tries thousands of passwords automatically against WordPress, SSH, FTP or email logins. Hyyat Host servers record failed logins and block an IP address that keeps failing. If you are blocked by mistake after forgetting your password, you will see a CAPTCHA to unblock yourself. Brute force is one of [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","template":"","meta":{"_eb_attr":"","inline_featured_image":false,"wprm-recipe-roundup-name":"","wprm-recipe-roundup-description":"","_templately_pack_id":"","_templately_imported_at":"","_templately_source":"","_templately_import_session_id":"","footnotes":""},"doc_category":[2219],"doc_tag":[],"class_list":["post-18362","docs","type-docs","status-publish","hentry","doc_category-2219"],"year_month":"2026-10","word_count":327,"total_views":"1","reactions":{"happy":"0","normal":"0","sad":"0"},"author_info":{"name":"ahmed fathy","author_nicename":"ahmed-fathy","author_url":"https:\/\/www.hyyat.com\/en\/author\/ahmed-fathy\/"},"doc_category_info":[{"term_name":"\u062d\u0645\u0627\u064a\u0629 \u0645\u0648\u0627\u0642\u0639 \u0627\u0644\u0627\u0646\u062a\u0631\u0646\u062a","term_url":"https:\/\/www.hyyat.com\/kb\/%d8%ad%d9%85%d8%a7%d9%8a%d8%a9-%d8%a7%d9%84%d9%85%d9%88%d8%a7%d9%82%d8%b9\/"}],"doc_tag_info":[],"knowledge_base_info":[],"knowledge_base_slug":[],"_links":{"self":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs\/18362","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/comments?post=18362"}],"version-history":[{"count":0,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs\/18362\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/media?parent=18362"}],"wp:term":[{"taxonomy":"doc_category","embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/doc_category?post=18362"},{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/doc_tag?post=18362"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}