Hi,
Im a bit nervous about a brute force attack occurring right now on my server...
(obs. sorry for my broken english)
I received a lot of emails saying:
login failures attempts to account
I checked the cPHulk and found the IP and blocked it using APF firewall
I set the cPHulk with the following:
Configure Settings
IP Based Brute Force Protection Period in minutes: 30
Brute Force Protection Period in minutes: 35
Maximum Failures By Account: 15
Maximum Failures Per IP: 8
Maximum Failures Per IP before IP is blocked for two week period: 20
Extend account lockout time upon additional authentication failures: Y
Send notification when brute force user is detected: Y
But, what's frightening meis that the brute force is trying the exact user names os my clients... How could it know that? Did I got cracked in a way the cracker could know only the real usernames but not the passwords?
Thanks!
Henrique.



LinkBack URL
About LinkBacks
is that the brute force is trying the exact user names os my clients... How could it know that? Did I got cracked in a way the cracker could know only the real usernames but not the passwords? 

Reply With Quote





