View Single Post
Old 10-01-2002, 04:26 AM  
Juge
Confirmed User
 
Join Date: Feb 2001
Posts: 1,917
For one thing, your system should be built to reject more than 1 connection with the same user/password at the same time from 2 IPs. Since these passwords are thrown to everyone, chances are that at least 2 people will attempt to log into the same one at the same time.

Also, how about some programming to detect when someone's user/pass is being used multiple times per day from different IPs. Hmmm.... do you really think the dude is travelling all over the world logging into your site? This should set off an alarm to check out the behaviour, if not bann it temporarily until it is resolved.

My
Juge is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote