2.7 brute force attack - how to stop

2.7 brute force attack - how to stop

eftir Ian L -
Number of replies: 4

I was getting an attack with hundreds of failed login errors in 2.3. I upgraded to 2.7 and am getting them still. I can't get the recaptcha to work. I enabled it and added keys but no it doesn't show.

I also limited the log ins to three failed attempts but that didn't help. The log in errors are coming from different IP addresses minute after minute.

please help

 

Average of ratings: -
In reply to Ian L

Re: 2.7 brute force attack - how to stop

eftir Ian L -

I have 46 pages of logs for today and about 44 of them are from these attacks. They are coming minute after minute.

Does the recatcha go on the log in page? http://www.mymoodle.com/login/index.php

I don't see it if it's supposed to.

Attachment bruteforceattack 2.png
In reply to Ian L

Re: 2.7 brute force attack - how to stop

eftir Howard Miller -
Mynd av Core developers Mynd av Documentation writers Mynd av Particularly helpful Moodlers Mynd av Peer reviewers Mynd av Plugin developers

Personally, I would get blocking the subnets in Apache and see if it calms down.