PDA

View Full Version : FlashFXP BETA Area / Password Guessing


bigstar
12-09-2002, 05:23 PM
9:00 am PST someone from the address 213-140-8-167.fastres.net started running a password guesser against the FlashFXP BETA download area. After roughly 3 hours of continual attacks apache gave out and the server crashed.

2:00 pm PST apache has been restart.

Please respect our server

DYN_DaTa
12-09-2002, 06:17 PM
Seems a static IP, save the logs and if the attack continues contact with his/her ISP about that, just my opinion.

DynAstY
12-09-2002, 11:10 PM
Call the FEDz! Update your UNIX software. Make the password count tries and ban IP for a day or so if failed attempts gets over like 25.

aCe2k
12-15-2002, 08:40 PM
25?

More like 5 times...
how hard can it be to type a bloody serial and a password?

And yes, sounds like apache needs a makeover too.

bigstar
12-16-2002, 08:10 AM
We've made some changes to better protect our server and will continue to do so.

We're currently looking into a password protection system that will auto block IP addresses after so many tries. Preferably something free or cheap.

ryan
12-17-2002, 02:45 AM
Originally posted by bigstar
We've made some changes to better protect our server and will continue to do so.

We're currently looking into a password protection system that will auto block IP addresses after so many tries. Preferably something free or cheap.

Take a look at http://www.cloverwheel.com/cloverpass/

Simple and sweet. I have a modified version which auto bans IP address.