2.7 brute force attack - how to stop

2.7 brute force attack - how to stop

لە لایەن Ian L -
Number of replies: 4

I was getting an attack with hundreds of failed login errors in 2.3. I upgraded to 2.7 and am getting them still. I can't get the recaptcha to work. I enabled it and added keys but no it doesn't show.

I also limited the log ins to three failed attempts but that didn't help. The log in errors are coming from different IP addresses minute after minute.

please help

 

تێکرایى نمرەپێدراوەکان: -
In reply to Ian L

Re: 2.7 brute force attack - how to stop

لە لایەن Ian L -

I have 46 pages of logs for today and about 44 of them are from these attacks. They are coming minute after minute.

Does the recatcha go on the log in page? http://www.mymoodle.com/login/index.php

I don't see it if it's supposed to.

Attachment bruteforceattack 2.png
In reply to Ian L

Re: 2.7 brute force attack - how to stop

لە لایەن Eduardo Kraus -
وێنەی Plugin developers وێنەی Testers

Hi

I developed a plug-in for it.

You are in https://github.com/EduardoKrausME/auth_bruteforce

Muito prazer, sou Eduardo Kraus
Teacher and loves Moodle

(Edited by Helen Foster to remove signature, since they are not allowed in the forums according to the Moodle.org site policy - original submission Saturday, 11 April 2015, 9:24 PM)