Web News


Oracle to compensate for I-flex offer delay
Oracle said Wednesday it will pay interest of 25 cents (11.35 rupees) per share to compensate shareholders in India's I-flex Solutions for a delay in a proposed open offer. Oracle, the world's biggest maker of database software, in September offered to pay up to $531 million to increase its stake in its majority-owned...

TCS to hire Science graduates
New Delhi: India’s largest software company, Tata Consultancy Services, also know to hire the largest number of freshers has announced its plan to hire science graduates to meet the demands of the rising tech industry. Labeled TCS Talent Transformation...

Ericsson opens research facility in Chennai
Ericsson India, a telecom major, Monday opened its research and development (R and D) facility here. Union Telecommunications Minister Dayanidhi Maran in the presence of Harald Falth, Swedish ambassador to India, opened the new R and D location, the third Ericsson facility here. Our continued investment in...

IP on your idiot box
Wire and Wireless India Limited (WWIL), now a restructured arm of Zee Network, is getting ready to dot Indian C&S (Cable & Satellite) landscape with triple plays services through a single Set Top Box (STB) and claims to be the only company so far for a digital cable licence in India. "Our STBs would be of three types and...


11.27.06


Protecting Your Site From Brute Force

By Mads Kristensen

On a website with the ability for users to logon, it is a good idea to have some sort of password policy.

The most widely used contains minimum requirements for the length of the password and that the individual characters must be a mixture of numbers, letters and special characters. This is pretty much standard and they make it much more difficult to break into your system.

Eventually, these passwords will be broken and for a brute force robot it's only a matter of time. That's why it is a good idea to protect against brute force attacks by limiting the number of retries you can take to login if you forget the right password.

I've written a few methods that limits the number of retries to 5. When the fifth bad attempt to logon is reached, you are unable to login to the user account for five minutes. No other users are affected, only the one that is being brute forced.

The Premier Event for Search Engine
Marketing & Optimization -
Register Now

The Code



Example of use



This is very simple to implement and should it be an issue to logon for the users, you can raise the threshold to 10 retries.

About the Author:
Mads Kristensen currently works as a Senior Developer at Traceworks located in Copenhagen, Denmark. Mads graduated from Copenhagen Technical Academy with a multimedia degree in 2003, but has been a professional developer since 2000. His main focus is on ASP.NET but is responsible for Winforms, Windows- and web services in his daily work as well. A true .NET developer with great passion for the simple solution.

http://www.madskristensen.dk/

About DevWebPro India
DevWebPro India is for professional developers ... those who build and manage applications and sophisticated websites. DevWebPro India delivers via news and expert advice New Strategies In Development.

DevWebPro India is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com NetworkNewz.com


-- DevWebPro India is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2006 iEntry, Inc.  All Rights Reserved  Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article


New Strategies In Development DevWebPro India News Archives About Us Feedback DevWebPro India Home Page About Article Archive News Downloads WebProWorld Forums Jayde iEntry Advertise Contact