Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

#1 2025-10-23 08:23:37

pexman
Member
Registered: 2016-02-27
Posts: 65

brutforce attacks on the admin log of my website

Two months ago, my ../textpattern page had around 70 hits, last month it had over 400, and this month it had almost 800. I would like something like this: after the first failed login, wait 1 minute before you can log in again, after the second, wait 3 minutes, and so on, or after the third failed login, no further attempts from that IP address, or any other protection. Maybe someone has a good suggestion.

Offline

#2 2025-10-23 15:31:16

colak
Admin
From: Cyprus
Registered: 2004-11-20
Posts: 9,316
Website GitHub Mastodon Twitter

Re: brutforce attacks on the admin log of my website

Do you have the ips of the attackers? Is there a pattern you can detect that you can block?

You may want to check my recent experience which I eventually solved using this directive.


Yiannis
——————————
NeMe | hblack.art | EMAP | A Sea change | Toolkit of Care
I do my best editing after I click on the submit button.

Offline

#3 2025-10-23 16:15:16

gaekwad
Server grease monkey
From: People's Republic of Cornwall
Registered: 2005-11-19
Posts: 4,538
Bitbucket GitHub

Re: brutforce attacks on the admin log of my website

pexman wrote #340975:

I would like something like this: after the first failed login, wait 1 minute before you can log in again, after the second, wait 3 minutes, and so on, or after the third failed login, no further attempts from that IP address, or any other protection

What web server are you using?

Offline

#4 Yesterday 15:43:25

pexman
Member
Registered: 2016-02-27
Posts: 65

Re: brutforce attacks on the admin log of my website

Thanks for your answers, Yes, you can exclude IP addresses directly via the server or via httpd. I do that too, but another form of protection would be a captcha or something else that prevents or hinders automated attacks via the console.

Offline

Board footer

Powered by FluxBB