In the world of shared hosting, security is a shared responsibility. While GHost Cloud ensures a secure environment, you must also take steps to protect your cPanel hosting account. This guide will walk you through essential security measures to safeguard your data and maintain the integrity of your website.
In this guide
Strong passwords and 2FA
One of the most fundamental steps in securing your cPanel hosting account is using strong passwords and enabling two-factor authentication (2FA). To change your cPanel password, log in to your cPanel account via the server hostname provided in your welcome email, using port 2083. Navigate to the 'Password & Security' section and follow the prompts to update your password. Ensure your new password is complex, combining upper and lower case letters, numbers, and special characters.
Enabling 2FA adds an additional layer of security by requiring a Time-based One-Time Password (TOTP) from an authentication app. To enable 2FA, go to the 'Two-Factor Authentication' section in cPanel, and follow the instructions to link your account with a TOTP app like Google Authenticator or Authy. This step ensures that even if someone obtains your password, they cannot access your account without the TOTP from your device.
SSL certificates
SSL certificates are crucial for encrypting data transferred between your website and its visitors. GHost Cloud offers AutoSSL with Let's Encrypt, which automatically installs and renews SSL certificates for your domains. To ensure that all traffic to your site is encrypted, you should force HTTPS. This can be done by redirecting all HTTP requests to HTTPS in your .htaccess file. For more detailed instructions, refer to our guides on installing and managing SSL certificates and forcing HTTPS on your website.
Directory privacy
Directory privacy allows you to password-protect specific directories on your server, adding an extra layer of security to sensitive areas such as staging sites or admin panels. To set this up, log into cPanel and navigate to the 'Directory Privacy' section. Select the directory you wish to protect, and follow the prompts to set a username and password. This feature is particularly useful for directories containing sensitive information or areas under development that should not be publicly accessible.
IP blocking
IP blocking is a powerful tool to prevent unwanted visitors from accessing your site. You can block specific IP addresses or ranges that are known to be malicious. To use this feature, go to the 'IP Blocker' section in cPanel and enter the IP addresses you wish to block. Regularly reviewing your server logs can help identify suspicious activity and determine which IPs to block. This proactive approach can significantly reduce the risk of attacks on your website.
Hotlink protection
Hotlink protection prevents other websites from directly linking to files on your site, such as images, which can save bandwidth and protect your content. To enable hotlink protection, go to the 'Hotlink Protection' tool in cPanel. Configure the settings to specify which file types to protect and which domains are allowed to link to your content. This feature is essential for preventing unauthorised use of your site's resources.
SpamAssassin
Troubleshooting
Occasionally, security measures can inadvertently lock you out of your own site. If you find yourself blocked by your own IP, check the 'IP Blocker' settings in cPanel to ensure your IP is not listed. For issues accessing password-protected directories, verify that you are using the correct credentials. If spam continues to be a problem despite configuring SpamAssassin, consider adjusting the sensitivity settings or consulting the cPanel security documentation for advanced solutions.
Related guides
- How to Log In to cPanel
- How to Secure Your WordPress Site
- cPanel Overview - A Complete Beginner's Guide
- How to Install and Manage SSL Certificates
- How to Force HTTPS on Your Website
Secure your hosting account today by implementing these strategies. For further assistance, explore our Shared Hosting options or contact our support team through our support ticket system for personalised help.
