Security & Firewall

How does brute-force protection work?

A brute-force attack is when an attacker's software tries thousands of username and password combinations, hoping to guess a valid login for your control panel, email, FTP or WordPress. Dirham A Day defends against this automatically.

Our servers run LFD (Login Failure Daemon) alongside the CSF firewall. LFD watches authentication attempts across services and, when it sees repeated failures from the same source, it temporarily blocks that IP address at the firewall, cutting the attack off before it can succeed.

This protects:

You do not need to switch anything on; it runs at the server level. You can add extra protection for your own applications, for example limiting login attempts to wp-login.php in WordPress and enabling two-factor authentication.

One side effect: if you or a staff member mistype a password several times, your own IP can be blocked temporarily and you will be unable to log in from that location. If that happens, find your IP (search "what is my IP") and contact our 24/7 team on WhatsApp +971 58 553 6767 or support@dirhamaday.ae to be unblocked immediately.

Still need a hand? Our UAE-based team is here 24/7.

Related articles

What firewall protects my hosting?Is my website scanned for malware?What is the ModSecurity web application firewall?How do I block a specific IP address?How do I enable two-factor authentication?