problem with this approach is the majority of automated scripts used
to make this kind of attack allow a programmable pause (and if they
dont it's trivial to add it).

(I used to experiment with these kind of tools when I was young and
foolish, allegedly.  For research purposes only of course ;)

Toby



Monday, February 24, 2003, 3:43:46 PM, you wrote:

BPR> The mechanism I use is to delay the response to an invalid 
BPR> userid/password by 5 or 10 seconds. It's not a solution but it makes it 
BPR> damn slow, hopefully too slow to be useful.

BPR> Brett
BPR> B)

BPR> Adam Chapman wrote:
>> Hey Everyone..
>> 
>> At the hack-proofing CFMX session at MXDU, Spike 
>> Mentioned a 'dictionary attack' or something similar
>> Where someone will pound your cf templates with lots-o
>> Username/password combos.. 
>> 
>> What are some of the methods peoples use to try and
>> Safeguard against this kind of thing..?
>> 
>> Regards,
>> Adam Chapman
>> 
>> Virtualtours.com.au
>> mailto:[EMAIL PROTECTED] 
>> Phone: 1300 366 122
>> (Int: +61 3 9720 5733)
>> Fax: +61 3 9720 6377)
>> 
>> 
>> ---
>> You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
>> To unsubscribe send a blank email to [EMAIL PROTECTED]
>> 
>> MX Downunder AsiaPac DevCon - http://mxdu.com/
>> 









 ---------------------------------------

             Life is poetry - 
               write it in your own words.

 ---------------------------------------

Toby Tremayne 
Technical Team Lead
Code Poet and Zen Master of the Heavy Sleep
Toll Solutions
154 Moray St
Sth Melbourne
VIC 3205
+61 3 9697 2317
0416 048 090
ICQ:  13107913


---
You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
To unsubscribe send a blank email to [EMAIL PROTECTED]

MX Downunder AsiaPac DevCon - http://mxdu.com/

Reply via email to