RE: Account Lockouts
"WebAppSecurity [Technicalinfo.net]" <[email protected]> Thu, 2 Dec 2004 09:51:51 -0000
| Newsgroups | gmane.comp.security.programming,gmane.comp.security.web-applications |
|---|---|
| Organization | [Technicalinfo.net] |
| Message-ID | <[email protected]> |
Hi Harrison, Checkout the section on "Account Lockout" in http://www.technicalinfo.net/papers/CustomHTMLAUthentication.html Cheers, Gunter > -----Original Message----- > From: Harrison Gladden [mailto:[email protected]] > Sent: 01 December 2004 17:52 > To: [email protected]; [email protected] > Subject: Account Lockouts > > Hello all, > > My question to the group is about handling account lock outs. > Here's the situation, assume there is a web interface that > lets users log in and do stuff, but the log-in process is > constrained by the network restrictions as well.. Meaning if > a user tries to log in X times in Y seconds and fails each > time, then the account get locked out. > > What are successfull techniques that could be used on the web > interface to avoid having a script run against it that would > potentially lock out 15000 user accounts, and create a > headache for the system administrators who have to manually > unlock each account? > > Also assume the current user account names are known by everyone. > > Possible techniques we've thrown around: > 1) Allow each user to pick their own username instead of > using a standard (i.e. First 3 letters of first name + Full last name) > > 2) Create a set time-out period for each account of X > (maybe an hour) > > > Hopefully my question makes sense. > > Thanks, > Harrison > -- > ___________________________________ > Harrison Gladden <[email protected]> > Computer Engineer & Science Major > ~Past experience: He who never makes > mistakes, never did anything that's worth.~ >