Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Stop Password Guessing
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Stop Password Guessing

 Post Reply Post Reply Page  <12
Author
fernan82 View Drop Down
Mod Builder Group
Mod Builder Group
Avatar

Joined: 17 November 2002
Location: United States
Status: Offline
Points: 362
Post Options Post Options   Thanks (0) Thanks(0)   Quote fernan82 Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2003 at 8:37pm

Originally posted by KCWebMonkey KCWebMonkey wrote:

well then, you prevent a certain IP address from logging in more that 5 times. there are always ways to make things work....

Yea, of course it can be done, my point is that I don't think it will be done on WWF cuz it basicly requires a new table on the database to record all the IPs with the user ID and the number of attempts, so since WWF is designed with MS Access in mind and I know how bruce is about this kind of thing I don't think it will be done...

I can think of another way to do it with just one new text field on the Author table and store all the IPs an attempts on the same field like 192.168.1.1:1;192.168.1.2:2 so you store the IP before the : and the number of attempts after the : and separate them with ; then the field could be reseted on every successful login... It will be a good idea but I don't think it will be done tho...

Also I think the security images (numbers) on the login is the best form of defense against that, it can still be done by hand but you know how long it would take to guess a password by hand?? I think it's almost impossible..... only think I would do to improve that feature is to change the images to something harder to read as it is not impossible for a bot to read those images...

What I would like to know is how MSN Chat do their bans, cuz if you go to a chat room there and start breaking havoc and come back to the same room they'll put a ban on you that's impossible to get out of it exept by switching PCs..... They don't ban your IP or your username and they don't use cookies neither, but the do something to your PC and  you won't be able to enter the room again unless you switch to a different PC or wait till the ban is over (24 hrs)... I think they use ActiveX for that and whatever they do is global for all users on the PC cuz even if you switch to another account it still won't work...

FeRnAN
Back to Top
fernan82 View Drop Down
Mod Builder Group
Mod Builder Group
Avatar

Joined: 17 November 2002
Location: United States
Status: Offline
Points: 362
Post Options Post Options   Thanks (0) Thanks(0)   Quote fernan82 Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2003 at 8:39pm
Originally posted by Bliss Bliss wrote:

Originally posted by Gullanian Gullanian wrote:

Ah yes but that way what if you hate someone else and login to there account 5 times a day on purpose to stop them coming on the site?

Yeah, but see, with my way, every successful login will set the counter to 0, so you can login as many times at you want if you know the right password.

You're missing something..... If I attempt to log in 5 times to your account then you won't be able to login successfully to reset the counter to 0.

FeRnAN
Back to Top
Bliss View Drop Down
Groupie
Groupie
Avatar

Joined: 25 April 2003
Location: United States
Status: Offline
Points: 181
Post Options Post Options   Thanks (0) Thanks(0)   Quote Bliss Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2003 at 8:41pm
Oops. Yeah, that would be a problem.
Hehehe...
Back to Top
wistex View Drop Down
Mod Builder Group
Mod Builder Group


Joined: 30 August 2003
Location: United States
Status: Offline
Points: 877
Post Options Post Options   Thanks (0) Thanks(0)   Quote wistex Quote  Post ReplyReply Direct Link To This Post Posted: 04 October 2003 at 12:26am

Originally posted by fernan82 fernan82 wrote:

What I would like to know is how MSN Chat do their bans, cuz if you go to a chat room there and start breaking havoc and come back to the same room they'll put a ban on you that's impossible to get out of it exept by switching PCs..... They don't ban your IP or your username and they don't use cookies neither, but the do something to your PC and  you won't be able to enter the room again unless you switch to a different PC or wait till the ban is over (24 hrs)... I think they use ActiveX for that and whatever they do is global for all users on the PC cuz even if you switch to another account it still won't work...

They may use an ActiveX control and put something in your Windows registry.

Back to Top
 Post Reply Post Reply Page  <12

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.