Page 1 of 1

Help against login brute force

Posted: Mon Mar 03, 2014 9:40 pm
by Renasc
Hello friends, some smartass is trying a lot of logins probably with some bruteforce/hack tool :evil:
The flood protector don't block him, i think its because he isn't using created accounts...

Image

If someone know something about it i'm all ears and ready to listen :mrgreen:

Re: Help against login brute force

Posted: Mon Mar 03, 2014 9:58 pm
by Zoey76
So how did he accessed you account names?

Re: Help against login brute force

Posted: Mon Mar 03, 2014 11:38 pm
by Renasc
Zoey76 wrote:So how did he accessed you account names?
nonono :!:

He is trying non created accounts, these accounts are not created.

Re: Help against login brute force

Posted: Tue Mar 04, 2014 12:06 am
by Aikimaniac
3 unsuccessful attempts and block in firewall rule for 24 hours, maybe IP range... btw..cant be that this is bot trying to log ? :)

Re: Help against login brute force

Posted: Tue Mar 04, 2014 1:50 am
by Renasc
Aikimaniac wrote:3 unsuccessful attempts and block in firewall rule for 24 hours, maybe IP range... btw..cant be that this is bot trying to log ? :)
this is automated, probably a software with login/pass list and maybe proxy list support...

Re: Help against login brute force

Posted: Tue Mar 04, 2014 12:32 pm
by Aikimaniac
Renasc wrote:
Aikimaniac wrote:3 unsuccessful attempts and block in firewall rule for 24 hours, maybe IP range... btw..cant be that this is bot trying to log ? :)
this is automated, probably a software with login/pass list and maybe proxy list support...
get apache log and block him on firewall...

Re: Help against login brute force

Posted: Tue Mar 04, 2014 1:12 pm
by angkor_tm
Aikimaniac wrote: get apache log and block him on firewall...
free proxy has not been canceled
I can use hundreds of different ip addresses....
Aikimaniac is right, you can use mod ipconnlimit for login port (for apache) or iptables (other firewall) for limit connection to login port.
Or you can use captcha mod for login.
The window that pops up before the login and password.
Or modified login window, but this is a modification of the client.

p.s. Or use L a m e Guard with autoupdater