Exceeded maximum allowed number of login attempts?

What do you want to see here? Some more categories, forums, and mods? Hmm...
User avatar
Jonathan
A Brave Victim
Posts: 3391
Joined: Thu Feb 03, 2005 12:50 am
Location: Not really lurking anymore

Re: Exceeded maximum allowed number of login attempts?

Post by Jonathan »

I can say now that it also happens to me. Unfortunately for whatever it is that causes this, my password is stronger than its hash. :)

*Stays outta here for now.*
ˌɑrməˈɡɛˌtrɑn
User avatar
Tank Program
Forum & Project Admin, PhD
Posts: 6711
Joined: Thu Dec 18, 2003 7:03 pm

Re: Exceeded maximum allowed number of login attempts?

Post by Tank Program »

It seems like there may be some sort of brute forcing system going on. I've patched phpBB so that it will record these failed login attempts to get the IPs, which I'll then ban.

These failed login attempts also seem to show up in the log files. The issue is that just this month there are 13398 logins and/or attempts. I'll have to find some sort of log analyser or write one to extract the IPs that could be behind this stuff. (Unless anyone knows of any existing software...)
Image
User avatar
Z-Man
God & Project Admin
Posts: 11589
Joined: Sun Jan 23, 2005 6:01 pm
Location: Cologne
Contact:

Re: Exceeded maximum allowed number of login attempts?

Post by Z-Man »

Waitwhat? I was right?

Probably not really related, but "View active topics" stopped working today. The list is empty now, but reliably showed all current topics previously.
Word
Reverse Adjust Outside Corner Grinder
Posts: 4258
Joined: Wed Jan 07, 2009 6:13 pm

Re: Two site problems

Post by Word »

the view active topics button seems to be broken for me...
User avatar
AI-team
Shutout Match Winner
Posts: 1020
Joined: Tue Jun 23, 2009 6:17 pm
Location: Germany/Munich
Contact:

Re: Two site problems

Post by AI-team »

Word wrote:the view active topics button seems to be broken for me...
for me as well ):
  
 
"95% of people believe in every quote you post on the internet" ~ Abraham Lincoln
 
 
User avatar
Tank Program
Forum & Project Admin, PhD
Posts: 6711
Joined: Thu Dec 18, 2003 7:03 pm

Re: Exceeded maximum allowed number of login attempts?

Post by Tank Program »

Hrmph. I upgraded phpBB while I was at it, that may be the cause.

Edit: Right. Got that fixed.
Image
User avatar
Tank Program
Forum & Project Admin, PhD
Posts: 6711
Joined: Thu Dec 18, 2003 7:03 pm

Re: Exceeded maximum allowed number of login attempts?

Post by Tank Program »

Apologies if anyone gets banned that's a real person. Contact me on IRC or Twitter if this happens.
Image
Word
Reverse Adjust Outside Corner Grinder
Posts: 4258
Joined: Wed Jan 07, 2009 6:13 pm

Re: Exceeded maximum allowed number of login attempts?

Post by Word »

I'm reading this with a proxy, otherwise I couldn't have found this at all. :/



edit: strange bug...whenever i hit submit i'm now redirected to a topic called "FISHY!"

edit2: now I'm back without proxy, thank you :)
User avatar
Jonathan
A Brave Victim
Posts: 3391
Joined: Thu Feb 03, 2005 12:50 am
Location: Not really lurking anymore

Re: Exceeded maximum allowed number of login attempts?

Post by Jonathan »

Word wrote:edit: strange bug...whenever i hit submit i'm now redirected to a topic called "FISHY!"
Probably a message. If you allow these little cracker fish to grow, they'll eventually get huge and destroy the ecosystem. Or something.

How does this banning work? It doesn't ban the first time an IP gets the exceeded message, right? Because that would ban everyone trying to login on their own account, if it had been hit before.
ˌɑrməˈɡɛˌtrɑn
User avatar
Tank Program
Forum & Project Admin, PhD
Posts: 6711
Joined: Thu Dec 18, 2003 7:03 pm

Re: Exceeded maximum allowed number of login attempts?

Post by Tank Program »

No, learned from accidentally banning Word. I haven't implemented anything yet, but it looks like there's a fairly specific criterion to look for. I don't want to write more here in case someone catches on...
Image
User avatar
Z-Man
God & Project Admin
Posts: 11589
Joined: Sun Jan 23, 2005 6:01 pm
Location: Cologne
Contact:

Re: Exceeded maximum allowed number of login attempts?

Post by Z-Man »

INW was also accidentally banned, just for the record.
User avatar
INW
Reverse Outside Corner Grinder
Posts: 1950
Joined: Tue Jul 07, 2009 4:10 pm
Location: Charlotte, NC, USA

Re: Exceeded maximum allowed number of login attempts?

Post by INW »

I was banned as well but Z-Man fixed it XD

Odd forums lately lol
User avatar
Tank Program
Forum & Project Admin, PhD
Posts: 6711
Joined: Thu Dec 18, 2003 7:03 pm

Re: Exceeded maximum allowed number of login attempts?

Post by Tank Program »

Right. Haven't had the time to workout the banning thing. Until I get around to that I'm aiming for a more sustainable approach. I've made some simple modifications to the login process. If anyone has any trouble logging in, please let me know.
Image
User avatar
Cosmic Dolphin
Round Winner
Posts: 377
Joined: Thu Dec 25, 2008 4:03 pm
Location: Ecuador

Re: Exceeded maximum allowed number of login attempts?

Post by Cosmic Dolphin »

Did it again to me when I logged in today. Took two tries because I couldn't read the captcha...
" Wise men talk because they have something to say; fools, because they have to say something."
-Plato
Ok, but why did I add this signature? I was like 15 and thought I was smart? What a brat.
User avatar
Tank Program
Forum & Project Admin, PhD
Posts: 6711
Joined: Thu Dec 18, 2003 7:03 pm

Re: Exceeded maximum allowed number of login attempts?

Post by Tank Program »

Has this happened to anybody else recently? Specifically those who went through the captcha once before and then wound up back at it after I made the modifications? I know it's happened to some folks, but I don't know if it was the captcha leftover from before...
Image
Post Reply