View ProjeQtOr On SourceForge.net
Support us on Capterra
ProjeQtOr free project management software - Preventing account lockout by DDOS - ProjeQtOr
 
 

Preventing account lockout by DDOS

More
10 Oct 2021 23:11 #1 by fathibn
Hi,
ProjeQtor beeing a web application that some of us expose to the internet. I recently got my admin account locked probably du to many wrong supplied passwords. I suggest to add some sort of "Challenge" on the login page like captcha to prevent accounts beeing locked.

Please Log in or Create an account to join the conversation.

More
15 Oct 2021 11:39 #2 by babynus
Some captcha will be very anoying for most users.
Enter a captcha for every connection is not desired. Some users connect several times a day... (and we do connect dozains of times a day...)
I would advide you to protect your server with fail2ban for instance, and set limit lower than limit in projector.
This way, a hacher you be banned (his IP is banned) after (for instance) 3 attempts, while ProjeQtOr account will be locked only after 5 attempts.
So youi'll have 2 attempts to connect and reset projeqtor wrong connection count...

Babynus
Administrator of ProjeQtOr web site
The following user(s) said Thank You: fathibn

Please Log in or Create an account to join the conversation.

More
17 Oct 2021 14:50 #3 by fathibn
Thank you @babynus. I will have to figure-out how to prevent fail2ban to block the ip address of my reverse proxy ssl which projeqtor is behind it. Butn that sound good until I figure out how to do saml authentication against lemonldap-ng, which will solve all the this problems and also the problems of several/tnes/hundreds connections a day.

Please Log in or Create an account to join the conversation.

More
18 Oct 2021 14:24 #4 by babynus
If you have a reverse prowy, it his his duty to block DDOS attacks

Babynus
Administrator of ProjeQtOr web site

Please Log in or Create an account to join the conversation.

More
18 Oct 2021 15:08 #5 by fathibn
:-) correct. Mine is just a ssl termination one, no packets mangling, no firewalling, no WAF.

Please Log in or Create an account to join the conversation.

Moderators: babynusprotion
Time to create page: 0.032 seconds

Cookies settings

×

Functional Cookies

Ce site utilise des cookies pour assurer son bon fonctionnement et ne peuvent pas être désactivés de nos systèmes. Nous ne les utilisons pas à des fins publicitaires. Si ces cookies sont bloqués, certaines parties du site ne pourront pas fonctionner.

Session

Please login to see yours activities!

Other cookies

Ce site web utilise un certain nombre de cookies pour gérer, par exemple, les sessions utilisateurs.