LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-25-2011, 12:10 PM   #16
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301

I don't applaud google, because they should be able to block brute force attacks like this.
 
Old 01-25-2011, 12:18 PM   #17
zer0signal
Member
 
Registered: Oct 2010
Location: Cleveland
Distribution: Slackware, Fedora, RHEL (4,5), LFS 6.7, CentOS
Posts: 258

Rep: Reputation: 29
I was kinda thinking the same thing, cause after 3 or 4 failed attempts doesn't it make you re authenticate with the system? So how do script kiddies get around that while brute force attacking? Use a proxy or bot net to change ip's once they have reached there failed attempt limit?
 
Old 01-25-2011, 12:27 PM   #18
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
It should be per user per day, not per-IP.
 
Old 01-25-2011, 12:29 PM   #19
zer0signal
Member
 
Registered: Oct 2010
Location: Cleveland
Distribution: Slackware, Fedora, RHEL (4,5), LFS 6.7, CentOS
Posts: 258

Rep: Reputation: 29
That would slow them down at least.
 
Old 01-25-2011, 12:29 PM   #20
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Quote:
Originally Posted by business_kid
The password was reasonable, but not perfect in terms of security. one letter and a random number string.
Sorry to revive a thread marked [SOLVED], but I'd argue that may be a fairly weak password. (Depends on length.)
 
Old 01-25-2011, 12:47 PM   #21
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
Use something like a password strength checker:
http://www.passwordmeter.com/

And make sure it says really strong.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
A bug.(i suppose).. harsha101087 Linux - Laptop and Netbook 1 12-16-2007 06:00 PM
what all these are suppose to mean ... alred Puppy 2 10-20-2006 07:34 AM
Are you suppose to be able to run X remotely? abefroman SUSE / openSUSE 15 05-09-2005 03:34 PM
I suppose you Americans have seen this floppywhopper General 9 11-18-2004 01:37 AM
Is a symlink suppose to blink? angmaya Linux - Newbie 5 10-18-2003 12:12 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:18 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration