Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

password cracking attempt at secure area

Status
Not open for further replies.

SM777

Technical User
Mar 7, 2001
208
GB
I'm experience a bad flood of password cracking attempts. What I usually do is to see the ip address and block it in the .htaccess file.

But this time I'm seeing about 40 or 50 different IP address worldwide hitting on me with random passwords.

Whats the best thing to do now and in the future?

for now I have stopped Apache and hope they'll go away.

In the future I guess I need some tool to block ip addresses dynamically. How's this done?

I have a 404 redirect that brings up a page if an incorrect password is entered whilst trying to access a secure area. Is this not enough?

Doesit not slow the &*^£*^$ers down? would the 404 redirect be better in say redirecting to a non existant site?

Help me out here guys its late and I dont want to stay up all night.

debian. apache 1.3.20
 
Correction: I have a 401 redirect that brings up a page if an incorrect password is..
 
I think that mod throttle thing may work. Cheers.

I'm still getting hit though. Let me run it by you again.

I have a private area secured by a .htaccess .htpasswd setup.

Chummy is using something like to brute force attempt to find a valid password.

I cant block his IP address because he is spoofing from a pool of hundreds of IP addresses. I cant complain to his ISP for the same reason.

Any other methods apart from converting to PHP?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top