Iprotect - Password Sentry - Pennywize - Trafficwize

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Cnetvisions
    Registered User
    • Apr 2004
    • 22

    #1

    Iprotect - Password Sentry - Pennywize - Trafficwize

    Good morning,
    I have some questions regarding
    Iprotect, Password Sentry, Pennywize & Trafficwize.

    When we started our first site in 1998
    we had a minimal amount of traffic and
    we used "PennyWize" to minimize the
    (bandwidth) damage and site slowdown
    when some of our passwords were occasionally
    listed on password trading sites.

    Although it was useless at stopping
    a "brute force attack", it did a good
    job of identifying traded passwords
    and suspending them once they had
    access to my members area.
    Another problem is that is uses
    "mod-rehahahahaha" which is memory
    intensive and can slow a server
    if a "brute force" attack is sustained
    for long periods of time.

    Since then I have also used "Password Sentry"
    with pretty much the same results in the sense
    that after they accessed the members area
    password sentry identified and suspended
    the traded password.

    The one good option password sentry has
    is it gives me more control on banning ip's.
    I can manually select how stringent to make
    it by banning ip's in any of the "four" groups
    of numbers that any ip has.
    The bad thing is that it uses
    "mod-r.e.w.r.i.t.e".

    I've found "Iprotect" to be the most effective
    as it uses the "apache module" instead of the
    "mod-r.e.w.r.i.t.e" so it doesn't tax the server
    in any substantial way.
    Although it still has the same downside of
    not stopping a "brute force attack" until
    they "breach" the members area.

    Currently, my main website uses about 50 gigs
    of bandwidth daily. My dedicated server has
    an Intel Dual Xeon 2.4 GHz with 2 gigs of ram.


    I would like to use "Pennywize" as I did years
    ago, as it is "browser based" and also gives me
    specific member usage that I find valuable.

    My concern is that I may have too much traffic
    (50 gigs daily) as my server may be easily
    "overwhelmed" by a sustained brute force attack.

    I've been told that it may not only cause my server
    to crash, but it may actually cause member content
    to be deleted during a brute force attack as
    pennywize tries to find enough "resources" to
    maintain it's function during the "mod-r.e.w.r.i.t.e"
    process.

    If anyone has had experience using "Pennywize"
    on a "bandwidth intensive site", or has heard of others
    using pennywize on a bandwidth intensive site, I would
    appreciate any feedback that you can offer.

    And lastly, if anyone has had any experience with
    "TrafficWize", I'd appreciate hearing your thoughts
    on that too.

    I appreciate any info you can share with me,
    Cnetvisions.
  • raymor
    Confirmed User
    • Oct 2002
    • 3745

    #2
    > in 1998 we had a minimal amount of traffic and
    > we used "PennyWize" ...
    > Although it was useless

    The hack scripts used by the script script kiddies and
    password sites have advanced a lot sense 1998.
    Pennydumb hasn't gotten any better.
    These scripts that are all clones of Pennydumb
    haven't improved much over the orignal either.
    Check out the modern way to protect your site.

    Go bang a Strongbox site with your favorite brute force or
    dictionary attack software. Don't worry about server resources,
    it's impossible for an attacker to load the server signifcantly,
    no matter how many proxies they're using.
    (Yeah, nowadays all the scripts use multiple proxies.
    Pennydumb didn't do too well at detecting an attacking IP in
    1998 and it now fails completely at detecting the 38 different
    IPs that may be used in a modern attack.)
    Download the most advanced attack software you can and load
    it up with 120 proxies. You'll quickly notice what real attackers
    notice about Strongbox, what normally makes them give up
    after a few minutes.

    Then take on of these Pennydumb sites and stick Strongbox
    on it, then run a report after 48 hours. What the fuck?!?!
    Where did all of those abused usernames come from?
    You THOUGHT pennydumb was protecting you, but the password
    sites figured out how to get around pennydumb in about 1999-2000.
    For historical display only. This information is not current:
    support@bettercgi.com ICQ 7208627
    Strongbox - The next generation in site security
    Throttlebox - The next generation in bandwidth control
    Clonebox - Backup and disaster recovery on steroids

    Comment

    • Cnetvisions
      Registered User
      • Apr 2004
      • 22

      #3
      Thanks I appreciate that,
      but does anyone from this board have
      any experience with using "Pennywize"
      on high bandwidth sites in terms of how
      the "mod-r.e.w.r.i.t.e" affects your server
      and files during brute force attacks?

      If you do, please share your expereinces.

      Cnetvisions.

      Comment

      Working...