Page 1 of 1

IP block or ban Function

PostPosted: Thu Mar 07, 2013 2:59 pm
by agegold
I'm a SubSonic user who donated before.

Since few days ago, looks like someone tries to login to my SubSonic server so many times, with wrong password.

So I'd like to kindly request you to make a function which can block specific IP for about 4~5 hours when some user failed to login more than five times.

Re: IP block or ban Function

PostPosted: Thu Mar 07, 2013 9:45 pm
by gurutech
Block the IP address on your firewall/router.

Re: IP block or ban Function

PostPosted: Fri Mar 08, 2013 5:13 am
by agegold
I use firewall but ip always change

Re: IP block or ban Function

PostPosted: Fri Mar 08, 2013 10:36 pm
by jol
agegold wrote: Since few days ago, looks like someone tries to login to my SubSonic server so many times, with wrong password.

So I'd like to kindly request you to make a function which can block specific IP for about 4~5 hours when some user failed to login more than five times.
I don“t see the benefit to ban the IP address if the user cannot authenticate successfully anway. Or does it lock out a legitimate user (not sure whether subsonic does that, there are pros and cons) because you shared credentials back some time?
Best regards, jol

Re: IP block or ban Function

PostPosted: Fri Mar 08, 2013 11:19 pm
by daneren2005
Ip banning is to prevent brute forcing. Right you you could pretty easily write a script which could try the most common 2-3 million passwords in less then a day, giving you access to 99% of the accounts on a standard server.