View Single Post
Old 2009-12-01, 09:23 AM   #10
gmr324
Aw, Dad, you've done a lot of great things, but you're a very old man, and old people are useless
 
gmr324's Avatar
 
Join Date: Sep 2006
Location: Boston, Mass
Posts: 21
Send a message via ICQ to gmr324
Quote:
You need a script that tracks access and stops it. If you just use htaccess, then the hacker can just keep hitting it with a brute
force until they find the right user/pass combo's. A script would block them after x attempts and make it tougher (not impossible).
This is a very good point. In fact, with Phantom Frog, we offer a Brute
Force Attack Protection feature. Too many 401 errors on an IP
address, will get the IP address blocked. If the ip address has been
associated with brute force, we remember/block the Ip address. It
doesn't matter whether there were 10K attempts or 5k attempts from
that Ip address ... it's IP address we block.

The other key to stopping the brute force attack is this: if the do get
a password Phantom Frog catches the abused password almost
immediately using High-Resolution Geo-IP tracking .... pretty soon the
hackers get frustrated and go somewhere else. Geo-IP tracks all
accesses to the members area down to the city level. We offer a free
trial of Geo-IP Pass Abuse Detection.

This is in addition to our Automated Member Support (AMS) feature
which provides 24/7 uninterrupted access to legit members and none to
hackers.

Thanks

George
__________________
Next Gen Password Protection
PhantomFrog
Email: George@PhantomFrog.com
gmr324 is offline   Reply With Quote