Leech protection prevents users from sharing passwords to protected directories by limiting how many times an account can log in within a two-hour window.
Enable leech protection
- Go to Security → Leech Protection.
- Select the password-protected directory you want to protect.
- Set the maximum number of logins allowed within two hours (for example 2).
- Enter an email address to receive alerts when the limit is exceeded.
- Choose whether to redirect violators to a URL or disable the compromised account.
- Click Enable.
Prerequisites
The directory must already be password-protected using Directory Privacy (Directory Indexing/Privacy). Leech protection adds an extra layer on top of basic authentication.
When alerts fire
If a user exceeds the login limit, you receive an email and can disable their directory access until you investigate whether credentials were shared.