Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

#1 Today 08:23:37

pexman
Member
Registered: 2016-02-27
Posts: 64

brutforce attacks on the admin log of my website

Two months ago, my ../textpattern page had around 70 hits, last month it had over 400, and this month it had almost 800. I would like something like this: after the first failed login, wait 1 minute before you can log in again, after the second, wait 3 minutes, and so on, or after the third failed login, no further attempts from that IP address, or any other protection. Maybe someone has a good suggestion.

Offline

#2 Today 15:31:16

colak
Admin
From: Cyprus
Registered: 2004-11-20
Posts: 9,314
Website GitHub Mastodon Twitter

Re: brutforce attacks on the admin log of my website

Do you have the ips of the attackers? Is there a pattern you can detect that you can block?

You may want to check my recent experience which I eventually solved using this directive.


Yiannis
——————————
NeMe | hblack.art | EMAP | A Sea change | Toolkit of Care
I do my best editing after I click on the submit button.

Offline

#3 Today 16:15:16

gaekwad
Server grease monkey
From: People's Republic of Cornwall
Registered: 2005-11-19
Posts: 4,535
Bitbucket GitHub

Re: brutforce attacks on the admin log of my website

pexman wrote #340975:

I would like something like this: after the first failed login, wait 1 minute before you can log in again, after the second, wait 3 minutes, and so on, or after the third failed login, no further attempts from that IP address, or any other protection

What web server are you using?

Offline

Board footer

Powered by FluxBB