Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - 10.11 Failled Login Attempts
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

10.11 Failled Login Attempts

 Post Reply Post Reply
Author
Ravage View Drop Down
Newbie
Newbie


Joined: 21 March 2006
Status: Offline
Points: 32
Post Options Post Options   Thanks (0) Thanks(0)   Quote Ravage Quote  Post ReplyReply Direct Link To This Post Topic: 10.11 Failled Login Attempts
    Posted: 01 May 2012 at 7:47pm
Hi
 
Just looking through the release notes and it says:
Quote 3. functions/functions_login.asp - updated to remove CAPTCHA test when incorrect login attempts get above that set in the admin area
 
I presume this is part of the SSL update (which I've not enabled yet) but could you tell me what is now supposed to happen now the captchya code has gone in this scenario - just worried about a brute force login attempt if the page never prevents someone from retrying logins?
 
We want to move to the SSL anyway (just not bought/configured the server for certification yet) but would even with SSL this behave differently?
 
Thanks in advance, Dom
 

 
 
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 01 May 2012 at 8:19pm
The removal of CAPTCHA security images has nothing to do with the new support for SSL.

The CAPTCHA security images has been removed as CAPTCHA is no longer a valid form of defence as sophisticated OCR software now used by hackers and spammers can read CAPTCHA codes that even a person can not read.

Instead Web Wiz Forums now includes now tools that include encrypted one time form fields, session tokens, and other methods to prevent automated programs such as brute force hacking tools.
Back to Top
Ravage View Drop Down
Newbie
Newbie


Joined: 21 March 2006
Status: Offline
Points: 32
Post Options Post Options   Thanks (0) Thanks(0)   Quote Ravage Quote  Post ReplyReply Direct Link To This Post Posted: 01 May 2012 at 8:43pm
Ok so does that mean the User Settings->Failled Login Attempts field is now a legacy unused field as for the life of me Ive just tried 15 different passwords and we got it set at only 3 - sorry if Im missing something here
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 01 May 2012 at 9:32pm
There is no CAPTCHA now in Web Wiz Forums, the setting now only sets a new security ID code for the account once the login limit is reached, which makes cracking an account more difficult and any auto login cookies for the account invalid.
Back to Top
Ravage View Drop Down
Newbie
Newbie


Joined: 21 March 2006
Status: Offline
Points: 32
Post Options Post Options   Thanks (0) Thanks(0)   Quote Ravage Quote  Post ReplyReply Direct Link To This Post Posted: 02 May 2012 at 10:35pm
Thanks Bruce:
Even though its not visible whats going on, its nice to know its properly handled - thanks for the explanation :)
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 03 May 2012 at 9:38am
I personally prefer the new methods as they are less intrusive, and also allows the forum to be used by partially sighted people which allows the forum to comply with disability laws that are in force in many countries.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.