2.7 brute force attack - how to stop

2.7 brute force attack - how to stop

Ian L發表於
Number of replies: 4

I was getting an attack with hundreds of failed login errors in 2.3. I upgraded to 2.7 and am getting them still. I can't get the recaptcha to work. I enabled it and added keys but no it doesn't show.

I also limited the log ins to three failed attempts but that didn't help. The log in errors are coming from different IP addresses minute after minute.

please help

 

評比平均分數: -
In reply to Ian L

Re: 2.7 brute force attack - how to stop

Ian L發表於

I have 46 pages of logs for today and about 44 of them are from these attacks. They are coming minute after minute.

Does the recatcha go on the log in page? http://www.mymoodle.com/login/index.php

I don't see it if it's supposed to.

附件 bruteforceattack 2.png
In reply to Ian L

Re: 2.7 brute force attack - how to stop

Eduardo Kraus發表於
Plugin developers的相片 Testers的相片

Hi

I developed a plug-in for it.

You are in https://github.com/EduardoKrausME/auth_bruteforce

Muito prazer, sou Eduardo Kraus
Teacher and loves Moodle

(Edited by Helen Foster to remove signature, since they are not allowed in the forums according to the Moodle.org site policy - original submission Saturday, 11 April 2015, 9:24 PM)