Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Stop Password Guessing
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Stop Password Guessing

 Post Reply Post Reply Page  12>
Author
Bliss View Drop Down
Groupie
Groupie
Avatar

Joined: 25 April 2003
Location: United States
Status: Offline
Points: 181
Post Options Post Options   Thanks (0) Thanks(0)   Quote Bliss Quote  Post ReplyReply Direct Link To This Post Topic: Stop Password Guessing
    Posted: 02 October 2003 at 2:20pm
To stop people from trying to guess passwords or to use password crackers, the forum should have a limit to how many times you enter your password, like PayPal does. If the user is the right user, then they can simply press the forgotten password button and retrieve their new password. The limit should be around five, and should not reset when you restart the computer, close the browser window, etc, but reset everyday instead. So how about it?
Hehehe...
Back to Top
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Posted: 02 October 2003 at 2:30pm
Or it could use a session to prevent the user trying to login again if they do it more than 5 times, I think this has been suggested before.
Back to Top
Bliss View Drop Down
Groupie
Groupie
Avatar

Joined: 25 April 2003
Location: United States
Status: Offline
Points: 181
Post Options Post Options   Thanks (0) Thanks(0)   Quote Bliss Quote  Post ReplyReply Direct Link To This Post Posted: 02 October 2003 at 2:39pm

I searched before I posted and didn't find anything similar, but of course I could have missed it. Even when I posted I was suprised no one had mentioned this before.

To get this to be foolproof, I think it might need a new db field. Every time the login button is hit, the data in the field increases by 1, and when the login is successful, it's reset to 0. That way the admin can set how many tries the user gets.

Hehehe...
Back to Top
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Posted: 02 October 2003 at 3:18pm
Ah yes but that way what if you hate someone else and login to there account 5 times a day on purpose to stop them coming on the site?
Back to Top
KCWebMonkey View Drop Down
Senior Member
Senior Member
Avatar
Go Chiefs!

Joined: 21 June 2002
Status: Offline
Points: 1319
Post Options Post Options   Thanks (0) Thanks(0)   Quote KCWebMonkey Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2003 at 2:10pm
well then, you prevent a certain IP address from logging in more that 5 times. there are always ways to make things work....
Back to Top
fernan82 View Drop Down
Mod Builder Group
Mod Builder Group
Avatar

Joined: 17 November 2002
Location: United States
Status: Offline
Points: 362
Post Options Post Options   Thanks (0) Thanks(0)   Quote fernan82 Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2003 at 6:31pm

Originally posted by KCWebMonkey KCWebMonkey wrote:

well then, you prevent a certain IP address from logging in more that 5 times. there are always ways to make things work....

Yea and there's always ways to get around things.... if somebody uses two proxies and switch back and forth for every attempt could beat that security, unless you record every failed attempt's IP which might not be a good idea...

FeRnAN
Back to Top
KCWebMonkey View Drop Down
Senior Member
Senior Member
Avatar
Go Chiefs!

Joined: 21 June 2002
Status: Offline
Points: 1319
Post Options Post Options   Thanks (0) Thanks(0)   Quote KCWebMonkey Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2003 at 6:53pm
Ok, how about after 5 failed attempts at a certain IP ( IP's are recorded on failed attempts), then the account must be re-activated via email.
Back to Top
Bliss View Drop Down
Groupie
Groupie
Avatar

Joined: 25 April 2003
Location: United States
Status: Offline
Points: 181
Post Options Post Options   Thanks (0) Thanks(0)   Quote Bliss Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2003 at 7:53pm

Originally posted by Gullanian Gullanian wrote:

Ah yes but that way what if you hate someone else and login to there account 5 times a day on purpose to stop them coming on the site?

Yeah, but see, with my way, every successful login will set the counter to 0, so you can login as many times at you want if you know the right password.

Hehehe...
Back to Top
 Post Reply Post Reply Page  12>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.