[BlueOnyx:04959] Exponential backoff on dictionay attacks

User Ernie ernie at info.eis.net.au
Mon Jul 5 18:38:42 -05 2010


Is it possible in the authentication layer that BX uses, to enable some form
of exponential retry back-off for failed password attempts from the same IP
address?

I know some scripts like dfix.sh and fail2ban try and catch failed
authentication attempts on some services, but I thought a more central
approach in an authentication layer might catch different sorts of attacks.

Backing off the retry interval, would help scripts scan logs etc. before the
attacker has gotten too far.

- Ernie.




More information about the Blueonyx mailing list