As part of the security mechanisms built into the LiteSpeed web server, visitors may occasionally be asked to complete a CAPTCHA verification before accessing a website. This protection is automatically triggered when the server detects behavior that may resemble an automated attack, excessive requests, or suspicious activity.
The goal of LiteSpeed reCAPTCHA protection is to distinguish legitimate visitors from bots and malicious traffic.
Table of Contents
What Is LiteSpeed reCAPTCHA?
LiteSpeed reCAPTCHA is a server-level protection mechanism that can automatically challenge visitors with a CAPTCHA verification when suspicious activity is detected.
Typical situations that may trigger a CAPTCHA challenge include:
- Excessive requests from a single IP address
- Brute-force login attempts
- Automated scanning activity
- Potential denial-of-service attacks
- Unusual browsing patterns
When activated, visitors must complete a CAPTCHA challenge before continuing to browse the website.
Adjusting the Protection Level
The protection level can be configured using rules placed in the website’s:
.htaccess
file.
This file is typically located in the website’s root directory:
public_html
Add the following rule:
<IfModule LiteSpeed>
LsRecaptcha 50
</IfModule>
Replace the value:
50
with a number between:
0 and 100
Available Values
| Value | Description |
|---|---|
| 0 | Completely disables LiteSpeed reCAPTCHA protection |
| 1-25 | Very low protection level |
| 26-50 | Moderate protection level |
| 51-75 | High protection level |
| 76-100 | Maximum protection level |
Disabling LiteSpeed reCAPTCHA
To completely disable LiteSpeed reCAPTCHA protection, use:
<IfModule LiteSpeed>
LsRecaptcha 0
</IfModule>
After saving the .htaccess file, the server will no longer display LiteSpeed CAPTCHA challenges.
Recommended Settings
For most websites, a moderate setting provides a good balance between security and usability.
Examples:
Low-Traffic Business Website
<IfModule LiteSpeed>
LsRecaptcha 25
</IfModule>
Standard Corporate Website
<IfModule LiteSpeed>
LsRecaptcha 50
</IfModule>
Frequently Targeted Website
<IfModule LiteSpeed>
LsRecaptcha 75
</IfModule>
Maximum Protection
<IfModule LiteSpeed>
LsRecaptcha 100
</IfModule>
Understanding False Positives
Increasing the protection level improves security but also increases the likelihood of false positives.
A false positive occurs when the server incorrectly identifies a legitimate visitor as suspicious and displays a CAPTCHA challenge.
At very high settings:
75–100
regular users may occasionally be challenged even though they are not performing any malicious activity.
If visitors frequently report CAPTCHA prompts, consider lowering the protection level.
Summary
LiteSpeed reCAPTCHA protection can be controlled through the website’s:
.htaccess
file using:
<IfModule LiteSpeed>
LsRecaptcha VALUE
</IfModule>
Where:
0disables the protection completely.100enables the highest protection level.- Values between
25and50are generally recommended for most websites.
Adjust the value according to your website’s traffic patterns and security requirements while keeping an eye on potential false positives.