Beefy Boxes and Bandwidth Generously Provided by pair Networks
go ahead... be a heretic

Re: Re: Password hacker killer

by Corion (Pope)
on Sep 07, 2003 at 14:27 UTC ( #289574=note: print w/replies, xml ) Need Help??

in reply to Re: Password hacker killer
in thread Password hacker killer

This method leads the way for an effective DOS - if I want to prevent you from logging in, I just write a script that repeatedly tries to log in as you, with a wrong password. You won't be able to ever get at your account again.

You need to block at least only a certain IP address, then only AOL users can block AOL users ...

perl -MHTTP::Daemon -MHTTP::Response -MLWP::Simple -e ' ; # The $d = new HTTP::Daemon and fork and getprint $d->url and exit;#spider ($c = $d->accept())->get_request(); $c->send_response( new #in the HTTP::Response(200,$_,$_,qq(Just another Perl hacker\n))); ' # web

Replies are listed 'Best First'.
Re: Re: Re: Password hacker killer
by allolex (Curate) on Sep 07, 2003 at 15:51 UTC

    Yes, thanks for pointing that out. It would therefore be logical to block the IP instead of the user for the same time period, or better yet block the combination of user/IP.


      this does not work, most of the automated cracking tools will use huge proxy lists to change the source IP of the attack after X attempts. You chase your own tail by limiting the user/ip block.


Log In?

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://289574]
and all is quiet...

How do I use this? | Other CB clients
Other Users?
Others having an uproarious good time at the Monastery: (7)
As of 2017-11-23 23:17 GMT
Find Nodes?
    Voting Booth?
    In order to be able to say "I know Perl", you must have:

    Results (343 votes). Check out past polls.