Jump to content

[Answered] Brute Force Vulnerability


mellofellow

Recommended Posts

I just had a thought.

 

In the forums we are required to post our username, server and domain sometimes.

So if I want to paralyze a site, could I not just attempt a few logins and thereby lock someone out of their account?

 

Is there a feature to reset via one's email (brute force counter not password) or security question that doesn't otherwise bother the admins?

Link to comment
Share on other sites

If someone tried that they'd only serve to block their own IP, If multiple people try and fail to access an account multiple times then the account gets locked, but it's only temporary. having the system you mention would be bad because then we'd basically be just as well off without a brute-force system.

  • Like 1
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...