There was indeed a problem with our proxy database server yesterday,
which we fixed. Strongbox includes two different features that should
prevent this from cauing a problem, but some installations had a bug such
that when our server was down some members had difficulty logging in.
Kudos to Mike at Phatservers.net, one of the most skilled hosts I know, for tracking
down the appropriate setting while I was away over the weekend and to Ramster for posting it.
Though the server should be good to go now, anyone with affected sites may
want to grab the updated proxycheck.pl and isp.pl files. The new files can be uploaded
to cgi-bin/sblogin/. If you installation is old enough to be installed in /login/ you don't
have or need these files.
I suggest renaming the two old files before uploading the new ones, so you can
easily switch back if you have difficulty logging in with the new ones.
The new ones will also make the login process faster after themember has already
logged in once, as part of the fix was related to the local caching of country,
proxy, and ISP information.
The updated files can be found at:
http://www.bettercgi.com/tmp/proxycheck.txt
http://www.bettercgi.com/tmp/isp.txt
Rename the files to ".pl" instead of ".txt".
Should any of you have any trouble in the future the phone number on the bettercgi.com
web site, 1-979-530-1300, rings my home phone, office phone, and cell phone,
so you should always be able to reach me at that number. If there's no answer,
which should be very rare, leave a message and I'll get right back to you.
Mainswitch, Strongbox has some code designed to set a limit on the server load
that can be generated by an attack, no matter how many thousands of proxies attack
at once. If you are seeing server load much above 1.0 even during a major attack
there are some settings that I can tweak. Though the default settings work quite
well for most people, variables such as your site's traffic and your server configuration
can influence that some and it sound sliek I should adjust yours a bit.
There's also a tradeoff of the number of logins Strongbox will allow
in a given period of time and the server load it can generate.
On a site with 10,000 members we might allow 10 logins per second,
which means allowing a higher server load than we would allow on
a small site siwht only 200 members, where we might allow 1 login per second.