Glossary Entry
What is Brute-Force Attack?
Brute-Force Attack without the jargon — the definition, the analogy, and why any site owner should care.
The short answer
A brute-force attack tries credentials over and over — thousands of guessed passwords, or leaked pairs replayed — until something opens.
The rest of the page opens it up — the mechanics, why a site owner should care, and one concrete example of it at work.
By the Hosting & Domains team · Reviewed 18 August 2026
0
Jargon left undefined
100+
Entries, all cross-linked
Real
Working examples
Free
To read, always
The whole thing is automated and entirely impersonal, hammering away at every login on the internet without pause: wp-login pages, SSH ports and mail servers alike. The variants have names of their own. Credential stuffing replays pairs taken from breach dumps. Password spraying takes a handful of obvious passwords and spreads them thinly across many accounts, staying beneath the lockout threshold.
The defences stack cheaply. A unique strong password ends guessing outright; attempt limits and fail2ban thin the traffic; 2FA makes even a correct guess worthless; key-only SSH ends the contest before it starts.
A way to picture Brute-Force Attack
A thief working down the street after dark with an enormous ring of keys, trying every door in turn. Tireless, mechanical and completely indifferent to who you are, and stopped dead by a lock that does not take standard keys.
Any analogy flattens the detail, naturally — but this one is solid enough to think with, and thinking is what a jargon buster is for.
Why this term earns a page
Your login pages sit out in this permanently. A proper defence stack turns a constant attack into constant log noise, and going without is how sites running admin and password123 quietly end up in a botnet.
Nobody expects you to work at this layer daily. The aim is recognising it when it explains something — and that moment is exactly when this page pays for itself.
How it turns up day to day
Overnight, an SSH log fills with thousands of failed attempts against common usernames. Under key-only authentication all of them are wasted motion, and fail2ban takes even the noise out of the log.
Scale that example across every website online and you have described the whole job of the concept in one stroke.
How Hosting & Domains deals with it
Here it largely looks after itself, since the defaults are sensible and the panel puts the controls within reach the moment you want them. Read on: Two-Factor Authentication, Firewall, SSH and Phishing.
NVMe storage and LiteSpeed caching sit under every tier, the smallest plan included — that is the floor here, not an upgrade.

A jargon buster from the people who answer the tickets
Sooner or later every confusing hosting term turns into a support ticket, so we defined the hundred commonest ones properly — once, in the same plain English we use with customers.
The rate you register at is the rate you renew at, so year two costs precisely what year one did — nothing lying in wait on the invoice.
- 100+ entries, plain English all the way
- Ordinary analogies, working examples
- Neighbouring ideas linked together
- Written by our own support engineers
Why Hosting & Domains
Standard on every plan
Cross-wired entries
Related terms point at each other, so one lookup compounds into working knowledge.
Tied to real hosting
Examples name platforms you would genuinely use, never an abstract diagram on a whiteboard.
Analogies that hold
Every concept comes with a mental model that returns exactly when you need it.
Clear about how deep to go
Most of these are recognise-level rather than operate-level, and every entry says which it is.
Stakes made explicit
More than what a thing is: the moments it turns out to be the answer to a problem you have.
This term, properly landed
Brute-Force Attack defined, pictured by analogy and located in your own panel — recognise-level after a single read.
Quick Start
Order placed to site online
- 1
Find it in your own account
Nothing teaches a hosting term faster than finding it in your own panel; five minutes of looking beats an hour of reading.
- 2
Check the defaults as they stand
The platform ships sensible defaults for this — check rather than assume, and your setup becomes something you know instead of hope.
- 3
Chase the neighbouring terms
Hosting terms travel in groups — Two-Factor Authentication, Firewall and SSH finish this one's picture, each a two-minute read away.
Built In
Fitted to every plan
- Softaculous included for one-click application installs
- Money back within 30 days on hosting plans, 7 on reseller
- WordPress and 400+ further applications installed in one click
- A renewal figure identical to the one you registered at
- Free SSL on every plan, reissued before the old one lapses
- Mailboxes that answer at the name you hold
- SSH, Git and Composer on the developer plans
- DDoS filtering absorbed at the network edge
- Spam and virus screening on every mailbox by default
- No set-up charge at any point, and no joining fee
Frequently Asked
The questions that come up most
Is anybody actually targeting my small site's login?
None of it is aimed at you: it is everything, indiscriminately, run by machine. That is reassuring once you see it clearly, because a mechanical attack falls to a mechanical defence, and strong passwords, attempt limits and 2FA are precisely that.
Can attempt limits lock me out of my own site?
Occasionally, and you can always get back in through the panel, an IP allow list, or by waiting the window out. That asymmetry is the entire point: a small nuisance for you, and arithmetic that never ends for somebody with thousands of guesses to spend.
Does hosting include mail?
Yes — every hosting plan includes mailboxes at your own name, with webmail, IMAP, POP and SMTP plus spam filtering on from the start. There is standalone email hosting too, for a name whose website lives somewhere else.
Can I transfer in a name I already own?
Yes, and it is routine. Unlock the name at your current registrar, take the auth code, and start the transfer from your client area. Whatever registration time remains carries over, and DNS keeps resolving the whole way through.
Keep reading
SSH (Secure Shell)
SSH opens an authenticated, encrypted line straight to a server's command line, where you can issue command…
Two-Factor Authentication (2FA)
2FA asks for a second proof alongside the password, usually a code from an app, so a stolen password on its…
How to Force HTTPS on Your Site
Step by step, with every snag flagged before you get to it.
Dedicated Cloud
Reserved resources with cloud flexibility — the step above a VPS.
Domain Names
Find, register and transfer names — year one free with annual hosting.
Changing hosts? Run through our checklist first.
A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.
Register it, then build on it.
NVMe hosting with SSL and the migration included, people answering at any hour, and a price that stays where it was.
View Dedicated Cloud plans