Restricting access to sensitive subdirectories on your website (such as /admin/, /wp-admin/, /staging/, or internal database tools) is one of the most effective ways to block hackers, automated bot scanners, and brute-force attacks.
DirectAdmin allows you to protect directories using Password Protection (HTTP Basic Authentication) or by configuring an IP Address Whitelist using .htaccess.
This guide will walk you through setting up both protection methods on your Cubes Hosting account.
Method 1: Password Protecting Directories in DirectAdmin (HTTP Basic Auth)
Password protecting a folder forces any web browser attempting to access that URL to enter a username and password before loading any files.
- Log in to your Cubes Hosting DirectAdmin Control Panel.
- Navigate to Account Manager > Password Protected Directories (or Directory Protection).
- Click Find Directory to Protect.
- Browse your file system and click Protect next to the folder you wish to lock down (e.g.,
public_html/admin/orpublic_html/staging/). - Configure the protection settings:
- Protected Directory Prompt: Enter a label for the popup dialog (e.g., Restricted Admin Area).
- Set Username & Password: Create an authorized user account for this folder.
- Check Protection Enabled and click Save.
Now, whenever anyone visits http://yourdomain.com/admin/, their browser will display an authentication popup requiring the password you set!
Method 2: IP Address Whitelisting via .htaccess
IP Whitelisting restricts folder access so that only specific IP addresses (such as your home or office internet connection) can view the files. All other IP addresses receive a 403 Forbidden error.
How to Create an IP Whitelist:
- Open your DirectAdmin File Manager.
- Navigate to the folder you want to restrict (e.g.
/public_html/admin/or/public_html/wp-admin/). - Create or edit the
.htaccessfile inside that folder. - Add the following Apache 2.4 IP restriction code:
# Restrict folder access to allowed IP addresses only
<RequireAll>
# Allow your home or office IP address
Require ip 203.0.113.50
# Allow a secondary staff IP address or subnet
Require ip 198.51.100.12
</RequireAll>
- Replace
203.0.113.50with your actual public IP address (you can find your public IP by visiting google.com and searching "what is my IP"). - Save the
.htaccessfile.
Combining Password Protection + IP Whitelisting
For maximum security on critical admin portals, combine both methods:
- Add an IP Whitelist in
.htaccessto block automated global bot networks. - Enable DirectAdmin Password Protection so that even if someone gets on your network, they still require a password to enter.
Related Guides
- Best Practices for Website Security: WordPress, Joomla, and Drupal
- How to Access SSH and SFTP on Your DirectAdmin Website
Conclusion
Locking down sensitive website folders takes less than two minutes. Use Password Protected Directories in DirectAdmin or restrict access to your IP address via .htaccess to keep your admin panels safe!
