Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
brute force protection captchas
#3
Alternative is to lockout and send reset email with timed token link.

I am against time throttles, as it can allow dos attacks to ties up many threads on your web server.

We can implement host blocking but any hacker worth their salt will be using a proxy anonymizer.
NEW: SA Admin Toolbar Plugin | View All My Plugins
- Shawn A aka Tablatronix
Reply


Messages In This Thread
brute force protection captchas - by shawn_a - 2013-03-13, 07:54:54
RE: brute force protection captchas - by Carlos - 2013-03-16, 17:50:35
RE: brute force protection captchas - by shawn_a - 2013-03-17, 00:35:06
RE: brute force protection captchas - by Carlos - 2013-03-17, 02:31:44
RE: brute force protection captchas - by shawn_a - 2013-03-17, 08:59:29
RE: brute force protection captchas - by shawn_a - 2013-03-22, 04:16:50



Users browsing this thread: 1 Guest(s)