Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Prevent Enumeration of Users

Status
Not open for further replies.

mezanine

IS-IT--Management
Jul 27, 2001
61
0
0
US
Is there a way to block the enumeration of users ie By doing this hackers could discover valid usernames on the system and attempt a brute force attatck. Any suggestions are welcome in preventing this.
 
Does the URL [ignore][/ignore] actually have to be valid?

If so, there's not much you can do short of have a script examine your httpd error log(s) for attempts to hit the per-user web pages of invalid users, then lock that IP out of your server.

If not, you could simply disable mod_userdir.


Want the best answers? Ask the best questions!

TANSTAAFL!!
 
How do I go about disabling mod_usedir?
 
If it's a DSO, don't load it. Comment out the line that looks like "LoadModule userdir_module modules/mod_userdir.so".

If it's compiled in statically, I think that removing the AddModule directive takes care of it. Not positive, though.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top