hmmm ... I'm not understanding something. If I have my CPHulk settings set as thus:
IP Based Brute Force Protection Period in minutes: 90
Brute Force Protection Period in minutes: 90
Maximum Failures By Account: 3
Maximum Failures Per IP: 3
Maximum Failures Per IP before IP is blocked for two week period: 9
Extend account lockout time upon additional authentication failures: checked
Send notification when brute force user is detected: checked
Why am I seeing entries in my logins like:
root h-66-166-56-233. system 0 2008-01-08 04:43:14
root h-66-166-56-233. system 0 2008-01-08 04:43:40
root h-66-166-56-233. system 0 2008-01-08 04:45:10
root h-66-166-56-233. system 0 2008-01-08 04:44:04
root h-66-166-56-233. system 0 2008-01-08 04:44:45
admin h-66-166-56-233. system 0 2008-01-08 04:45:27
admin h-66-166-56-233. system 0 2008-01-08 04:45:35
root h-66-166-56-233. system 0 2008-01-08 04:43:31
admin h-66-166-56-233. system 0 2008-01-08 04:45:52
root h-66-166-56-233. system 0 2008-01-08 04:44:29
root h-66-166-56-233. system 0 2008-01-08 04:44:12
root h-66-166-56-233. system 0 2008-01-08 04:45:02
root h-66-166-56-233. system 0 2008-01-08 04:43:48
root h-66-166-56-233. system 0 2008-01-08 04:44:54
admin h-66-166-56-233. system 0 2008-01-08 04:45:44
root h-66-166-56-233. system 0 2008-01-08 04:43:56
admin h-66-166-56-233. system 0 2008-01-08 04:45:19
root h-66-166-56-233. system 0 2008-01-08 04:43:23
admin h-66-166-56-233. system 0 2008-01-08 04:46:00
root h-66-166-56-233. system 0 2008-01-08 04:44:21
root h-66-166-56-233. system 0 2008-01-08 04:44:37
admin h-66-166-56-233. system 0 2008-01-08 04:46:11
22 attempts in 3 minutes - all from the same IP address. This IP should now be on a two week lock-down, right?



LinkBack URL
About LinkBacks
Reply With Quote







