Page 1 of 1

Brute Force Detection and or disabling Admin direct login

PostPosted: Thu Mar 17, 2011 2:10 am
by Tanner Williamson
Two security questions / ideas I wanted to bring for discussion.

Is it possible to disable admin login completely, or at least lock down the IP addresses to private network IP only as permitted for admin login?

I would also like to protect Subsonic against brute force attacks. I suppose that if failed logins were logged to a file, we could implement integration to RFXN's Brute Force Detect + Advanced Policy Firewall, or even ConfigServer Firewall. Both APF and CSF are powerful front ends for iptables functionality, generally built into modern linux kernels.

RFXN's Brute Force Detect / BFD
RFXN's Advanced Policy Firewall / APF

ConfigServer's ConfigServer Firewall / CSF

PostPosted: Thu Mar 17, 2011 6:30 am
by GJ51
That's not possible at this time as far as I know. I just use a complex password, such as, xg3uRdOv1L3k and trust that nobody's really interested enough in wasting the time it would take to crack it just to hear some music.

Even when I had links to my sites posted as part of my signature here on the forums, I never had any problems with unauthorized intrusions.