The mechanism I use is to delay the response to an invalid userid/password by 5 or 10 seconds. It's not a solution but it makes it damn slow, hopefully too slow to be useful.

Brett
B)

Adam Chapman wrote:
Hey Everyone..

At the hack-proofing CFMX session at MXDU, Spike Mentioned a 'dictionary attack' or something similar
Where someone will pound your cf templates with lots-o
Username/password combos..


What are some of the methods peoples use to try and
Safeguard against this kind of thing..?

Regards,
Adam Chapman

Virtualtours.com.au
mailto:[EMAIL PROTECTED] Phone: 1300 366 122
(Int: +61 3 9720 5733)
Fax: +61 3 9720 6377)



--- You are currently subscribed to cfaussie as: [EMAIL PROTECTED] To unsubscribe send a blank email to [EMAIL PROTECTED]

MX Downunder AsiaPac DevCon - http://mxdu.com/



--
Brett Payne-Rhodes
Eaglehawk Computing
t: +61 (0)8 9371-0471
f: +61 (0)8 9371-0470
m: +61 (0)414 371 047
e: [EMAIL PROTECTED]
w: www.ehc.net.au


--- You are currently subscribed to cfaussie as: [EMAIL PROTECTED] To unsubscribe send a blank email to [EMAIL PROTECTED]

MX Downunder AsiaPac DevCon - http://mxdu.com/

Reply via email to