Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Worrying
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Worrying

 Post Reply Post Reply Page  <1234 7>
Author
l15aRd View Drop Down
Groupie
Groupie


Joined: 24 May 2002
Location: England
Status: Offline
Points: 121
Post Options Post Options   Thanks (0) Thanks(0)   Quote l15aRd Quote  Post ReplyReply Direct Link To This Post Posted: 22 September 2003 at 9:47am

we use Go.stats as it's a totally seperate site, which logs IP's/Country/Browser, etc, plus our hardware and software firewall logs

Access, and it's outside of the webroot area...



Edited by l15aRd

DrunkenTechie.net

You can logoff, but you can never leave
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 22 September 2003 at 1:11pm
Originally posted by l15aRd l15aRd wrote:

how about adding a number of password tries into a future version then it suspends the account, pending an unlock by admin/moderators, abit like NT based network logins?

The problem being if it is the admin account that the person is trying to guess if the account is suspended after 3 attempts the admin can't login to re-activate their own account.

But I shall look into other solutions.
Back to Top
Eftie View Drop Down
Groupie
Groupie


Joined: 17 March 2003
Location: Netherlands
Status: Offline
Points: 140
Post Options Post Options   Thanks (0) Thanks(0)   Quote Eftie Quote  Post ReplyReply Direct Link To This Post Posted: 23 September 2003 at 12:20am

Originally posted by -boRgThe problem being if it is the admin account that the person is trying to guess if the account is suspended after 3 attempts the admin can't login to re-activate their own account.<BR><BR>But I shall look into other solutions.<BR>[/QUOTE -boRgThe problem being if it is the admin account that the person is trying to guess if the account is suspended after 3 attempts the admin can't login to re-activate their own account.

But I shall look into other solutions.
[/QUOTE wrote:


Maybe not a suspension but an hour time out??

Maybe not a suspension but an hour time out??

Eftie
Back to Top
Badaboem View Drop Down
Senior Member
Senior Member


Joined: 12 April 2002
Location: Netherlands
Status: Offline
Points: 600
Post Options Post Options   Thanks (0) Thanks(0)   Quote Badaboem Quote  Post ReplyReply Direct Link To This Post Posted: 23 September 2003 at 3:43am

the sollution could be a newly generated long password after first three attempts. It will be mailed to the admin who obviously only has access to his mail account.

Only problem is not all folks have the email function enabled.

Another fix could be a simple database table with yes/no since the hacker probably wasn't able to download the database. Yes for suspended (lockdown of admin acount after three false logins). Then u could simply change yes to no it in the database and quickly change your password.



Edited by Badaboem
Back to Top
michael View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 April 2002
Location: United States
Status: Offline
Points: 4670
Post Options Post Options   Thanks (0) Thanks(0)   Quote michael Quote  Post ReplyReply Direct Link To This Post Posted: 23 September 2003 at 9:36am
This all could become an administration nightmare though, people knowing that can keep doing it and you never have peace with your password. One idea could be, that admins are able to associate their account with one or more ip classes. so if you i.e. have in your account that you can only login from 125.2.*.* as well as 128.0.*.* (multiple cause you might use more then one computer) sure problem if you are somewhere else you could not log in but to have it as an option maybe.
For the lockout itself, you could add the ip address of the user to the block list after three attempts, that way they would have to change their ip every time which would become annoying for the hacker last but not least, deny login attempts for like 20 minutes after three attempts so brite force attacks would take forever
Back to Top
l15aRd View Drop Down
Groupie
Groupie


Joined: 24 May 2002
Location: England
Status: Offline
Points: 121
Post Options Post Options   Thanks (0) Thanks(0)   Quote l15aRd Quote  Post ReplyReply Direct Link To This Post Posted: 23 September 2003 at 1:02pm

Sounds like the dail-back on a RAS server, sounds good the adding the IP to a banned list after three attempts, and to add maybe send out an alert to a certain group, like in mine,

We have the admin group, but I did'nt want to risk having more than one user with admin rights, so I created a super moderator group, they can do everything in every forum, bar administer the back end settings, so if someone does hack their password, the most they can do is deleted/edit some posts and delted the SM account (which is no biggy).

The three main owners all know the admin password and if they want to make changes we consult each other first.

This is turning into quite a good brain storming session... :)



Edited by l15aRd

DrunkenTechie.net

You can logoff, but you can never leave
Back to Top
God_Struth View Drop Down
Senior Member
Senior Member
Avatar

Joined: 07 August 2003
Location: United Kingdom
Status: Offline
Points: 218
Post Options Post Options   Thanks (0) Thanks(0)   Quote God_Struth Quote  Post ReplyReply Direct Link To This Post Posted: 23 September 2003 at 7:31pm
The IP solution is a no goer, there are simply too many people on dial up who will never have a static IP address, which would be required to be able to do this.


Simplest way to keep security tight is to create another "power" user and use it as your main login, only using the admin account to make back end changes. Most people go and give a hacker a head start by calling themselves "Admin" or "Boss Dude" (or something else which implies authority).


A hacker is half way there once he finds out which account to target, so make it difficult by losing the easy to guess Admin names..


(PS. Have a real real hard to guess password, using numbers and letters )
Back to Top
He02 View Drop Down
Newbie
Newbie


Joined: 23 September 2003
Location: United Kingdom
Status: Offline
Points: 13
Post Options Post Options   Thanks (0) Thanks(0)   Quote He02 Quote  Post ReplyReply Direct Link To This Post Posted: 23 September 2003 at 7:54pm
[QUOTE=l15aRd]

I'm using 7.01, I agree with the brute force thing, most probably Lopthcrack or something similar.

QUOTE]

 Lopthcrack remotely ??

Back to Top
 Post Reply Post Reply Page  <1234 7>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.