new login feature - beware

Announcements and for questions/problems..
Post Reply
User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

new login feature - beware

Post by bad_brain »

I have noticed a lot of failed login attempts in the logs, to avoid brute forcing attempts I have implemented a feature that bans a user with 3 failed login attempts for 30 minutes now... :wink:

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

bah, ban them for a year, will give them some time to think xD
"The best place to hide a tree, is in a forest"

User avatar
computathug
Administrator
Administrator
Posts: 2693
Joined: 29 Mar 2007, 16:00
17
Location: UK
Contact:

Post by computathug »

Thats another good idea b_b, any way of implimenting the security on suck-o to the highest standard even though it may sometimes be a little time consuming, is a good idea at times like this.

Great handling of the total situation at hand.

I will hopefully be back online permanently later today and it will be good to catch up :wink:
The devil can cite Scripture for his purpose.
-- William Shakespeare, "The Merchant of Venice"
https://tshirt-memes.com

User avatar
lilrofl
Siliconoclast
Siliconoclast
Posts: 1363
Joined: 28 Jan 2009, 17:00
15
Location: California, USA
Contact:

Post by lilrofl »

well banned for 30 minutes should give them plenty of time to commit their password to memory me thinks...

User avatar
moudy
Technology Enthusiast
Technology Enthusiast
Posts: 688
Joined: 10 Feb 2009, 17:00
15
Location: Beirut, Lebanon

Post by moudy »

p4inl0v3r wrote:just a suggestion ....

incase of such more than 3 failed attempts , instead of banning , an email to the user can be sent with his passwrd .... if the guy is genuine and in trbl then he is helped .... otherwise also no prob ;)
well some services like hotmail, have an option where you ask them to send you the password to your e-mail, I never noticed some thing like that over here, but yeah its a good idea.
mahmoud_shihab@hotmail.com

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

well, the point is that those failed login attempts are not made by users that maybe had a drink too much or have trouble remembering their password....those are automated login attempts. maybe 40 different IPs have been banned in the meantime (just for 1 hour, those bans are not permanent), I have checked about 30 of them and NONE was an IP of a known user.

but ok, the "lost password" function is something I will try to set up, good idea... :wink:

Post Reply