Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 08-20-2010, 02:47 PM   #1
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,823
What to do when people don't stop trying to get into your member area by guessing user/passwords?

53480 logins unsuccessful.
39141 different usernames tried to login from 1567 different IP ranges from 131 ISPs in 7 countries.

and this goes on since 3-4 days, thanks to Strongbox no one seemed to be successful so far.

can i make this stop somehow? it's annoying
MaDalton is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-20-2010, 03:58 PM   #2
Porko
SeeMyBucks.com
 
Porko's Avatar
 
Industry Role:
Join Date: Sep 2002
Location: USA
Posts: 4,014
Strongbox is fantastic. Send an email to these guys, they will give you some tips.
__________________
Porko is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-20-2010, 04:00 PM   #3
notime
Confirmed User
 
notime's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: cyberspace
Posts: 8,019
Spank them !
notime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-20-2010, 04:01 PM   #4
scarlettcontent
www.scarlettcontent.net
 
scarlettcontent's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Pleiades
Posts: 6,031
display a captcha.
__________________


Scarlett Content - Adult Content Provider - High Quality Adult Stock Content for your Websites, Mobile Media and Print.

Over 3 Million Images (14,000 photo sets) over 5000 Videos - Many Niches, US-2257, Awesome Prices.
Over 40 years in the adult industry.

[email protected] Follow us on twitter.
scarlettcontent is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-20-2010, 04:40 PM   #5
damnage
Confirmed User
 
Industry Role:
Join Date: Aug 2008
Location: Bottom of dung heap
Posts: 512
Maybe a Vbulletin style login where if you get 5 tries before having to wait 15 mins?
__________________
Email: Jaypas {:at:] hot mail {:dot:} com
damnage is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-20-2010, 04:42 PM   #6
vano
Confirmed User
 
vano's Avatar
 
Join Date: Apr 2005
Posts: 209
ban IP after 5 tries
vano is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2010, 01:34 AM   #7
yal
Confirmed User
 
Join Date: Aug 2008
Posts: 134
is there any alternative to strong box ?
yal is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2010, 01:37 AM   #8
bja
Registered User
 
Join Date: Apr 2010
Location: Illinois, USA
Posts: 16
Quote:
Originally Posted by yal View Post
is there any alternative to strong box ?
Any half-competent admin can properly configure a *nix box to keep up to date and use sane configurations.
bja is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2010, 02:14 AM   #9
seeandsee
Check SIG!
 
seeandsee's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Europe (Skype: gojkoas)
Posts: 50,945
Quote:
Originally Posted by MaDalton View Post
53480 logins unsuccessful.
39141 different usernames tried to login from 1567 different IP ranges from 131 ISPs in 7 countries.

and this goes on since 3-4 days, thanks to Strongbox no one seemed to be successful so far.

can i make this stop somehow? it's annoying
who have such options and use it for hacking one pass?
__________________
BUY MY SIG - 50$/Year

Contact here
seeandsee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2010, 02:49 AM   #10
erooup
Confirmed User
 
erooup's Avatar
 
Industry Role:
Join Date: Jul 2010
Posts: 512
You were most likely featured on a password sharing list. There wont come many sales out of it, but its still creating awareness of your site.
erooup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2010, 04:08 AM   #11
Paul Markham
Too old to care
 
Paul Markham's Avatar
 
Industry Role:
Join Date: Jun 2001
Location: On the sofa, watching TV or doing my jigsaws.
Posts: 52,943
Ask Ray at Strongbox, he will have the answer.

Other than consigning the email notifications straight to the Delete box, what's the problem?
Paul Markham is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2010, 06:39 AM   #12
MaDalton
I am Amazing Content!
 
MaDalton's Avatar
 
Industry Role:
Join Date: Feb 2004
Posts: 39,823
Quote:
Originally Posted by Porko View Post
Strongbox is fantastic. Send an email to these guys, they will give you some tips.
so far Strongbox is holding up good. but we also use 16 digit random user/password combinations, so all these attempts are pretty fruitless anyways


Quote:
Originally Posted by notime View Post
Spank them !
i wish i could


Quote:
Originally Posted by scarlettcontent View Post
display a captcha.
Strongbox does that


Quote:
Originally Posted by vano View Post
ban IP after 5 tries
Strongbox does that


Quote:
Originally Posted by erooup View Post
You were most likely featured on a password sharing list. There wont come many sales out of it, but its still creating awareness of your site.
so i should be thankful? ;)


Quote:
Originally Posted by Paul Markham View Post
Ask Ray at Strongbox, he will have the answer.

Other than consigning the email notifications straight to the Delete box, what's the problem?
it's annoying me that i get hundreds of emails - lol
MaDalton is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2010, 06:47 AM   #13
~Ray
visit hardlinks.org
 
~Ray's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Las Vegas , Nv >>> [email protected] or icq 94994627 anytime
Posts: 18,362
Ask yourself this. How many attempts should I give a real member to remember and login to my website?

3? 5? 7? 10?

Well, once that ip reaches the limit you set, then bann that ip from your server.

Over time, the number of failed attempts will drop.


I am not Ray from strongbox



~Ray

Last edited by ~Ray; 08-21-2010 at 06:49 AM..
~Ray is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2010, 07:22 AM   #14
wizzart
scriptmaster
 
wizzart's Avatar
 
Industry Role:
Join Date: May 2006
Location: Serbia
Posts: 5,237
block IP if he try 5 times unsuccessful.
wizzart is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2010, 07:43 AM   #15
woj
<&(©¿©)&>
 
woj's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
50k requests is nothing, I wouldn't worry about it...
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager
woj is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2010, 07:50 AM   #16
ottopottomouse
She is ugly, bad luck.
 
ottopottomouse's Avatar
 
Industry Role:
Join Date: Jan 2010
Posts: 13,177
Move the login page if it just bashing away at you like someone has left a computer running with a set of lists.
__________________
↑ see post ↑
13101
ottopottomouse is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2010, 07:55 AM   #17
Ecchi22
Too lazy to set a custom title
 
Ecchi22's Avatar
 
Industry Role:
Join Date: Nov 2005
Posts: 10,012
Quote:
Originally Posted by seeandsee View Post
who have such options and use it for hacking one pass?
Its not very hard to spread a botnet to 2k machines ;)
__________________
Ecchi22 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2010, 08:35 AM   #18
Stephen
Consigliere
 
Industry Role:
Join Date: Feb 2003
Posts: 1,771
Quote:
Originally Posted by MaDalton View Post
so i should be thankful? ;)
Maybe

I was once a fan of bogus paysites that were really free sites / affiliate site hubs...

Toss an htaccess / htpasswd gateway on it and add a number of logins, then share those logins on various boards (one each so you can track the source of your new visitors) and watch your visitor count climb.

This traffic can be traded or sold, but is also productive and often overlooked
Stephen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2010, 08:37 AM   #19
gleem
Confirmed User
 
gleem's Avatar
 
Industry Role:
Join Date: Jun 2001
Location: Sunny Land
Posts: 5,593
use proxypass, it will ban the IP's trying to get in after a few attempts, has black list updated all the time with known Proxies that are used for brute force.
__________________




Contact me: \\// E: webmaster /at/ unprofessional.com
gleem is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-21-2010, 12:32 PM   #20
gmr324
Confirmed User
 
Industry Role:
Join Date: Aug 2006
Posts: 1,199
Quote:
is there any alternative to strong box ?
PhantomFrog is a very viable aletrnative to Strongbox. Frog offers the most accurate
password abuse detection available with our unique Hi-Res Geo-IP Tracking. Furthernore,
it provides 24/7 uninterrupted access to your members area for legit members and none
to hackers with our Automated Member Support (AMS) feature. This way, webmasters
can focus on more important work like site content and promotion rather than password
management and damage control.

Finally, Frog has Bruteforce Attack and Bandwidth Abuse Protection. Too many 401 errors
on an IP address, will get the IP address blocked if the IP address has been associated
with brute force, we remember/block the IP address.

Frog offers a Free Trial that installs easily. You don't have to disable any current pass
protection system you're currently using so you get a live side-by-side parallel comparison of the two systems.

To learn more about Phantom Frog or see our webmaster testimonials, click here

To install a Free Trial of PhantomFrog, click here

Last edited by gmr324; 08-21-2010 at 12:37 PM..
gmr324 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.