![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Join Date: Oct 2001
Location: Canada
Posts: 114
|
Brute Force Attacks... What's Considered High?
I have a new pay site up... yesterday I had 110,000 attempts to hack into the members area.
I don't think this number is high enough to worry about yet, but what is? A million? 3 million? How high does it get? How many proxies can these fuckers set up, and how many are out there? I'm not terribly worried about it at this point because I have fraud protection up... muliple ips downloading from the same user/pass get removed, but when I get more members this could get out of hand.... or if the number of brute force attacks increases exponnentially. lol How many failed logins did you have yesterday? How many does it have to be before bothering to set it up software like proxypass?
__________________
Ambition is as common as dirt. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Join Date: Jun 2002
Location: My Coffin
Posts: 1,227
|
It only takes 1 kiddy script hacker using a shit load of proxies to bring your server down to a slow crawl.
Once the hacker community finds out you don't have any brute force protection you are going to be a prime target. The one day you awake to a $1,000.00 + bandwidth bill. Just put something like http://www.stopthathacker.com on the site and sleep easier. Hugs, Danielle |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Join Date: Oct 2001
Location: Canada
Posts: 114
|
Hmmm.... today it's just over a million.
Well fuck me gently with a wire brush. Bandwidth? Who cares... it's just a text page, and if they get in the username/pass gets deleted at a certain level. What worries me is the load on the server. No problems at all yet, but this could obviously become an issue. Thank you.
__________________
Ambition is as common as dirt. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Join Date: Jul 2002
Location: Magrathea
Posts: 6,493
|
Anyone with a brute forcer, a few proxies and DSL can do 30,000-60,000/hour without breaking a sweat. I think the answer to your question is: when it effects server performance.
SpaceAce |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 | |
Confirmed User
Join Date: Jun 2002
Location: My Coffin
Posts: 1,227
|
Quote:
If you want to test your server just go post password requests on all the hacker boards and sit back and see at what point your server slows or crashes. Hugs, Danielle |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 | |
Confirmed User
Join Date: Oct 2001
Location: Canada
Posts: 114
|
Quote:
![]()
__________________
Ambition is as common as dirt. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Join Date: Jun 2002
Location: My Coffin
Posts: 1,227
|
Also, the larger your password file the larger the server load. Every password attempt causes your password file to be loaded in to memory and parsed.
Hugs, Danielle |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Join Date: Feb 2003
Location: In Your GF's Panty.
Posts: 1,192
|
DONT MAKE YOUR MEMBERS AREA Bruteforceable !!
This is the solution ... Exemple : Make http(s) form login not classical pop-up login And use random image picker for people MUST enter theirs user pass after this number image randomly picked user =gfy pass= test the number on the image= 000000-999999 Click Here Enter here and move you members area to random name www.example.com/your member area daily random word/content.htm if you dont move your private area to random name your files can be BRUTE FORCEABLE i mean this form login will not work if someone know your data files images where it is .. www.exemple.com/members/1.jpg -> Can be always brute forcable So you have to use random words for your files sorry for bad english but this is the simple solution !! And Never let Your users choose their pass let them use their e-mail and pass e-mailed them AlphaNumeric : GfY12Xrt So crackers will never guess what kind of pass they will use for brute force ..
__________________
This place is for RENT |
![]() |
![]() ![]() ![]() ![]() ![]() |