Anti Brute-Force
Posted: Sat Mar 04, 2017 5:01 pm
Quote from the announcement:
I don't quite understand the red-highlighted part in combination with the blue-highlighted part, as it explains how the password was stolen.
As a general suggestion, I wanted to bring up to disable an account after 3-5 consecutive failed attempts. E-Mail with unlock-link would be generated, to ensure that the person with the right E-Mail can unlock the account. Maybe even send an E-Mail for each failed attempt, in case someone tries to 'hack' it bit by bit.
Edit: Or maybe just for Staff Members if the rest could cause too much hassle/confusion?
At 3 pm, I was notified of the breach. Being rather surprised by the situation and trying to figure out what happened, things didn't look good. Half an hour later, I contacted uakf.b informing him about the breach and we have taken measures to counter the "hack" (which, in fact, was just a mere brute-force of a forum user's password; how exactly he got the user's password is unknown to us though).
I don't quite understand the red-highlighted part in combination with the blue-highlighted part, as it explains how the password was stolen.
As a general suggestion, I wanted to bring up to disable an account after 3-5 consecutive failed attempts. E-Mail with unlock-link would be generated, to ensure that the person with the right E-Mail can unlock the account. Maybe even send an E-Mail for each failed attempt, in case someone tries to 'hack' it bit by bit.
Edit: Or maybe just for Staff Members if the rest could cause too much hassle/confusion?