You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This bundle doesn't take into consideration that different IP addresses might be used to brute force a specific username. However, blocking the account based on multiple attempts for a specific username, irrespective of the IP address, creates another problem i.e. user A can attempt to log in as user B, hence blocking access for user B. To overcome this, we need to make sure that access for user B is allowed from a pre-saved/whitelisted IP address.
Do you have any opinion/thoughts on the matter?
The text was updated successfully, but these errors were encountered:
ahmadnazir
changed the title
Bruteforce attack using different IPs
Brute force attack using different IPs
Dec 9, 2014
I would like it a lot if there's some in-memory counter somewhere that checks how many failed attempts a specific username has had for the last 24/48 hours.
This would prevent a lot of the 'tor' attacks imo.
This bundle doesn't take into consideration that different IP addresses might be used to brute force a specific username. However, blocking the account based on multiple attempts for a specific username, irrespective of the IP address, creates another problem i.e. user A can attempt to log in as user B, hence blocking access for user B. To overcome this, we need to make sure that access for user B is allowed from a pre-saved/whitelisted IP address.
Do you have any opinion/thoughts on the matter?
The text was updated successfully, but these errors were encountered: