Locked out by Brute Force Protection and I can not access the cPanel/WHM control panel. What should I do?

If you, or a client, has been locked out/blocked by Brute Force Protection and you have no access to the cPanel/WHM control panel, you will see/get the following message:

This account is currently locked out because a brute force attempt was detected. Please wait 10 minutes and try again. Attempting to login again will only increase this delay. If you frequently experience this problem.

When WHM locks out a user, especially root, the best possible option is to wait for 10 minutes to see if the account will be unlocked. If the locks persists, the only possible way to clear your IP from the blacklist is through SSH. If you can access the server through shell/SSH do the following steps:

  1. Login to MySQL prompt using the following command:
    • mysql
  2. We need to backup CPHulk database tables. At MySQL prompt, enter the following commands (in this order):
    • BACKUP TABLE brutes TO /usr/local/src;
    • BACKUP TABLE logins TO /usr/local/src;
  3. The following commands will clear all entries in CPHuld database
    • DELETE FROM brutes;
    • DELETE FROM logins;
  4. Exit MySQL prompt using the following command
    • quit
