problem with this approach is the majority of automated scripts used to make this kind of attack allow a programmable pause (and if they dont it's trivial to add it).
(I used to experiment with these kind of tools when I was young and foolish, allegedly. For research purposes only of course ;) Toby Monday, February 24, 2003, 3:43:46 PM, you wrote: BPR> The mechanism I use is to delay the response to an invalid BPR> userid/password by 5 or 10 seconds. It's not a solution but it makes it BPR> damn slow, hopefully too slow to be useful. BPR> Brett BPR> B) BPR> Adam Chapman wrote: >> Hey Everyone.. >> >> At the hack-proofing CFMX session at MXDU, Spike >> Mentioned a 'dictionary attack' or something similar >> Where someone will pound your cf templates with lots-o >> Username/password combos.. >> >> What are some of the methods peoples use to try and >> Safeguard against this kind of thing..? >> >> Regards, >> Adam Chapman >> >> Virtualtours.com.au >> mailto:[EMAIL PROTECTED] >> Phone: 1300 366 122 >> (Int: +61 3 9720 5733) >> Fax: +61 3 9720 6377) >> >> >> --- >> You are currently subscribed to cfaussie as: [EMAIL PROTECTED] >> To unsubscribe send a blank email to [EMAIL PROTECTED] >> >> MX Downunder AsiaPac DevCon - http://mxdu.com/ >> --------------------------------------- Life is poetry - write it in your own words. --------------------------------------- Toby Tremayne Technical Team Lead Code Poet and Zen Master of the Heavy Sleep Toll Solutions 154 Moray St Sth Melbourne VIC 3205 +61 3 9697 2317 0416 048 090 ICQ: 13107913 --- You are currently subscribed to cfaussie as: [EMAIL PROTECTED] To unsubscribe send a blank email to [EMAIL PROTECTED] MX Downunder AsiaPac DevCon - http://mxdu.com/
