What to do when people don't stop trying to get into your member area by guessing user/passwords?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • MaDalton
    I am Amazing Content!
    • Feb 2004
    • 39861

    #1

    What to do when people don't stop trying to get into your member area by guessing user/passwords?

    53480 logins unsuccessful.
    39141 different usernames tried to login from 1567 different IP ranges from 131 ISPs in 7 countries.

    and this goes on since 3-4 days, thanks to Strongbox no one seemed to be successful so far.

    can i make this stop somehow? it's annoying
    AmazingContent.com - providing only the best content and service since 2003
    Monetize your content on Veegaz.com - one of Germanies largest VOD sites
    Got German traffic? We convert it into money for you!
    Email: oltecconsult [at] gmail [dot] com
  • Porko
    SeeMyBucks.com
    • Sep 2002
    • 4014

    #2
    Strongbox is fantastic. Send an email to these guys, they will give you some tips.

    Comment

    • notime
      Confirmed User
      • Jun 2003
      • 8025

      #3
      Spank them !

      Comment

      • scarlettcontent
        www.scarlettcontent.net
        • Mar 2006
        • 6031

        #4
        display a captcha.


        Scarlett Content - Adult Content Provider - High Quality Adult Stock Content for your Websites, Mobile Media and Print.

        Over 3 Million Images (14,000 photo sets) over 5000 Videos - Many Niches, US-2257, Awesome Prices.
        Over 40 years in the adult industry.

        [email protected] Follow us on twitter.

        Comment

        • damnage
          Confirmed User
          • Aug 2008
          • 512

          #5
          Maybe a Vbulletin style login where if you get 5 tries before having to wait 15 mins?
          Email: Jaypas {:at:] hot mail {:dot:} com

          Comment

          • vano
            Confirmed User
            • Apr 2005
            • 210

            #6
            ban IP after 5 tries
            Celebrity TrafficPremium PPSTabloidDollars.com

            Comment

            • yal
              Confirmed User
              • Aug 2008
              • 134

              #7
              is there any alternative to strong box ?
              Asian Sex Thumbs at asianmuffin.com
              Asian Porn at asianpornarchive.net
              AsianTraffic.net

              Comment

              • bja
                Registered User
                • Apr 2010
                • 16

                #8
                Originally posted by yal
                is there any alternative to strong box ?
                Any half-competent admin can properly configure a *nix box to keep up to date and use sane configurations.
                Security Auditing and Remote Administration

                Comment

                • seeandsee
                  Check SIG!
                  • Mar 2006
                  • 50945

                  #9
                  Originally posted by MaDalton
                  53480 logins unsuccessful.
                  39141 different usernames tried to login from 1567 different IP ranges from 131 ISPs in 7 countries.

                  and this goes on since 3-4 days, thanks to Strongbox no one seemed to be successful so far.

                  can i make this stop somehow? it's annoying
                  who have such options and use it for hacking one pass?
                  BUY MY SIG - 50$/Year

                  Contact here

                  Comment

                  • erooup
                    Confirmed User
                    • Jul 2010
                    • 512

                    #10
                    You were most likely featured on a password sharing list. There wont come many sales out of it, but its still creating awareness of your site.

                    Comment

                    • Paul Markham
                      Too old to care
                      • Jun 2001
                      • 52942

                      #11
                      Ask Ray at Strongbox, he will have the answer.

                      Other than consigning the email notifications straight to the Delete box, what's the problem?



                      Blowout deal. 880 videos, 2,400 image sets, plus many RAW videos. $500.
                      PM me for a deal. Skype Paulmarkham70

                      Comment

                      • MaDalton
                        I am Amazing Content!
                        • Feb 2004
                        • 39861

                        #12
                        Originally posted by Porko
                        Strongbox is fantastic. Send an email to these guys, they will give you some tips.
                        so far Strongbox is holding up good. but we also use 16 digit random user/password combinations, so all these attempts are pretty fruitless anyways


                        Originally posted by notime
                        Spank them !
                        i wish i could


                        Originally posted by scarlettcontent
                        display a captcha.
                        Strongbox does that


                        Originally posted by vano
                        ban IP after 5 tries
                        Strongbox does that


                        Originally posted by erooup
                        You were most likely featured on a password sharing list. There wont come many sales out of it, but its still creating awareness of your site.
                        so i should be thankful? ;)


                        Originally posted by Paul Markham
                        Ask Ray at Strongbox, he will have the answer.

                        Other than consigning the email notifications straight to the Delete box, what's the problem?
                        it's annoying me that i get hundreds of emails - lol
                        AmazingContent.com - providing only the best content and service since 2003
                        Monetize your content on Veegaz.com - one of Germanies largest VOD sites
                        Got German traffic? We convert it into money for you!
                        Email: oltecconsult [at] gmail [dot] com

                        Comment

                        • ~Ray
                          visit hardlinks.org
                          • Jun 2003
                          • 18361

                          #13
                          Ask yourself this. How many attempts should I give a real member to remember and login to my website?

                          3? 5? 7? 10?

                          Well, once that ip reaches the limit you set, then bann that ip from your server.

                          Over time, the number of failed attempts will drop.


                          I am not Ray from strongbox



                          ~Ray
                          Last edited by ~Ray; 08-21-2010, 05:49 AM.
                          Adult Backlinks for Adult Websites - Testimonials Available

                          Comment

                          • wizzart
                            scriptmaster
                            • May 2006
                            • 5246

                            #14
                            block IP if he try 5 times unsuccessful.
                            BimboZone

                            Comment

                            • woj
                              <&(©¿©)&>
                              • Jul 2002
                              • 47882

                              #15
                              50k requests is nothing, I wouldn't worry about it...
                              Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
                              Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
                              Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager

                              Comment

                              • ottopottomouse
                                She is ugly, bad luck.
                                • Jan 2010
                                • 13177

                                #16
                                Move the login page if it just bashing away at you like someone has left a computer running with a set of lists.
                                ↑ see post ↑
                                13101

                                Comment

                                • Ecchi22
                                  Too lazy to set a custom title
                                  • Nov 2005
                                  • 10012

                                  #17
                                  Originally posted by seeandsee
                                  who have such options and use it for hacking one pass?
                                  Its not very hard to spread a botnet to 2k machines ;)

                                  Comment

                                  • Stephen
                                    Consigliere
                                    • Feb 2003
                                    • 1771

                                    #18
                                    Originally posted by MaDalton
                                    so i should be thankful? ;)
                                    Maybe

                                    I was once a fan of bogus paysites that were really free sites / affiliate site hubs...

                                    Toss an htaccess / htpasswd gateway on it and add a number of logins, then share those logins on various boards (one each so you can track the source of your new visitors) and watch your visitor count climb.

                                    This traffic can be traded or sold, but is also productive and often overlooked

                                    Comment

                                    • gleem
                                      Confirmed User
                                      • Jun 2001
                                      • 5593

                                      #19
                                      use proxypass, it will ban the IP's trying to get in after a few attempts, has black list updated all the time with known Proxies that are used for brute force.




                                      Contact me: \\// E: webmaster /at/ unprofessional.com

                                      Comment

                                      • gmr324
                                        Confirmed User
                                        • Aug 2006
                                        • 1199

                                        #20
                                        is there any alternative to strong box ?
                                        PhantomFrog is a very viable aletrnative to Strongbox. Frog offers the most accurate
                                        password abuse detection available with our unique Hi-Res Geo-IP Tracking. Furthernore,
                                        it provides 24/7 uninterrupted access to your members area for legit members and none
                                        to hackers with our Automated Member Support (AMS) feature. This way, webmasters
                                        can focus on more important work like site content and promotion rather than password
                                        management and damage control.

                                        Finally, Frog has Bruteforce Attack and Bandwidth Abuse Protection. Too many 401 errors
                                        on an IP address, will get the IP address blocked if the IP address has been associated
                                        with brute force, we remember/block the IP address.

                                        Frog offers a Free Trial that installs easily. You don't have to disable any current pass
                                        protection system you're currently using so you get a live side-by-side parallel comparison of the two systems.

                                        To learn more about Phantom Frog or see our webmaster testimonials, click here

                                        To install a Free Trial of PhantomFrog, click here
                                        Last edited by gmr324; 08-21-2010, 11:37 AM.

                                        Comment

                                        Working...