Good morning,
I have some questions regarding
Iprotect, Password Sentry, Pennywize & Trafficwize.
When we started our first site in 1998
we had a minimal amount of traffic and
we used "PennyWize" to minimize the
(bandwidth) damage and site slowdown
when some of our passwords were occasionally
listed on password trading sites.
Although it was useless at stopping
a "brute force attack", it did a good
job of identifying traded passwords
and suspending them once they had
access to my members area.
Another problem is that is uses
"mod-rehahahahaha" which is memory
intensive and can slow a server
if a "brute force" attack is sustained
for long periods of time.
Since then I have also used "Password Sentry"
with pretty much the same results in the sense
that after they accessed the members area
password sentry identified and suspended
the traded password.
The one good option password sentry has
is it gives me more control on banning ip's.
I can manually select how stringent to make
it by banning ip's in any of the "four" groups
of numbers that any ip has.
The bad thing is that it uses
"mod-r.e.w.r.i.t.e".
I've found "Iprotect" to be the most effective
as it uses the "apache module" instead of the
"mod-r.e.w.r.i.t.e" so it doesn't tax the server
in any substantial way.
Although it still has the same downside of
not stopping a "brute force attack" until
they "breach" the members area.
Currently, my main website uses about 50 gigs
of bandwidth daily. My dedicated server has
an Intel Dual Xeon 2.4 GHz with 2 gigs of ram.
I would like to use "Pennywize" as I did years
ago, as it is "browser based" and also gives me
specific member usage that I find valuable.
My concern is that I may have too much traffic
(50 gigs daily) as my server may be easily
"overwhelmed" by a sustained brute force attack.
I've been told that it may not only cause my server
to crash, but it may actually cause member content
to be deleted during a brute force attack as
pennywize tries to find enough "resources" to
maintain it's function during the "mod-r.e.w.r.i.t.e"
process.
If anyone has had experience using "Pennywize"
on a "bandwidth intensive site", or has heard of others
using pennywize on a bandwidth intensive site, I would
appreciate any feedback that you can offer.
And lastly, if anyone has had any experience with
"TrafficWize", I'd appreciate hearing your thoughts
on that too.
I appreciate any info you can share with me,
Cnetvisions.
I have some questions regarding
Iprotect, Password Sentry, Pennywize & Trafficwize.
When we started our first site in 1998
we had a minimal amount of traffic and
we used "PennyWize" to minimize the
(bandwidth) damage and site slowdown
when some of our passwords were occasionally
listed on password trading sites.
Although it was useless at stopping
a "brute force attack", it did a good
job of identifying traded passwords
and suspending them once they had
access to my members area.
Another problem is that is uses
"mod-rehahahahaha" which is memory
intensive and can slow a server
if a "brute force" attack is sustained
for long periods of time.
Since then I have also used "Password Sentry"
with pretty much the same results in the sense
that after they accessed the members area
password sentry identified and suspended
the traded password.
The one good option password sentry has
is it gives me more control on banning ip's.
I can manually select how stringent to make
it by banning ip's in any of the "four" groups
of numbers that any ip has.
The bad thing is that it uses
"mod-r.e.w.r.i.t.e".
I've found "Iprotect" to be the most effective
as it uses the "apache module" instead of the
"mod-r.e.w.r.i.t.e" so it doesn't tax the server
in any substantial way.
Although it still has the same downside of
not stopping a "brute force attack" until
they "breach" the members area.
Currently, my main website uses about 50 gigs
of bandwidth daily. My dedicated server has
an Intel Dual Xeon 2.4 GHz with 2 gigs of ram.
I would like to use "Pennywize" as I did years
ago, as it is "browser based" and also gives me
specific member usage that I find valuable.
My concern is that I may have too much traffic
(50 gigs daily) as my server may be easily
"overwhelmed" by a sustained brute force attack.
I've been told that it may not only cause my server
to crash, but it may actually cause member content
to be deleted during a brute force attack as
pennywize tries to find enough "resources" to
maintain it's function during the "mod-r.e.w.r.i.t.e"
process.
If anyone has had experience using "Pennywize"
on a "bandwidth intensive site", or has heard of others
using pennywize on a bandwidth intensive site, I would
appreciate any feedback that you can offer.
And lastly, if anyone has had any experience with
"TrafficWize", I'd appreciate hearing your thoughts
on that too.
I appreciate any info you can share with me,
Cnetvisions.

Comment