Help - Search - Members - Calendar
Full Version: Preventing brute force attacks
The Planet Forums > Security > General Security
bustygirl
I have been attacked by brute force hackers several times in the last couple of weeks since getting my rackshack server (yes I'm a newbie).

I have had 4 password posted on password boards.

I want to stop this and have no idea how short of importing logs into excel and manually adding to apf. This is becoming cumbersome and I know there must be an easy, cheap and/or free way to help me with this.

If anyone knows of one amy help would be greatly appreciated.

Thanks!!
arvand
is this root password for SSH?

I havent done this but im sure its an easy process... only allow your IP to access SSH.
bustygirl
they are doing it through my sign-in page in my members area
naramation
Are they brute forcing an HTTP Authentication system? Who made it? I suggest using a custom solution that will disable accounts when more than 3 passwords are tried.

And when you let members make passwords, make sure they are good passwords. There are some scripts that will check this out there.
bustygirl
Are they brute forcing an HTTP Authentication system?

I have no idea.

Who made it?

Globill (for a short time longer) and 2000 Charge.

I suggest using a custom solution that will disable accounts when more than 3 passwords are tried.

I understand, what I need is a program/script cheap/free that will do this.
CornFused
bustygirl, where's the avitar??????icon_biggrin.gif
bustygirl
??
CornFused
QUOTE
Originally posted by bustygirl
??

<-------Avitar, that little picture over there!
kamihacker
if not using SSL (just like the BRAND NEW livesupport) could be easily sniffed with a tool on the Internet, no matter if we're in switched network, I don't know how rackshack handles this kind of stuff or they just don't care about people sniffing around

as for me I'd be interested in knowing if they're snorting for people trying to deface or crack boxes

I know it's not among the Terms of Service, but I'd like to know

any word from HeadSurfer about this?
marktopia
[Mod Edit] Spamvertising is bad m'kay!!![/Mod Edit]
REBIS
Yeah, I'll bet you have installed it on your domains. It's your damn script!

Quit posting this ad of yours all over our forum, which is obviously the only reason you joined, and take your covert self-promotion campaign somewhere else! mad.gif


QUOTE
Originally posted by marktopia
The best tool to protect your site and also stop brute force and proxy attacks and others is install rcp 4 wish is robot control pro 4 een perl script available at www.robotcontrolpro.com ...

Its a very good website protection script written in perl.
i have it installed on my domains.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.