in reply to Password hacker killer
You could watch for many failed attempts from the same IP address, but that will get false positives on proxies, and false negatives from AOL or dialup customers. Definitely don't bother with cookies or referer: any bad guy worth their salt is going to strip those. In fact, it's trivial to construct a LWP-based bot that blows both of those off.
-- Randal L. Schwartz, Perl hacker
Be sure to read my standard disclaimer if this is a reply.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: •Re: Password hacker killer
by abell (Chaplain) on Sep 08, 2003 at 07:45 UTC | |
|
Re: •Re: Password hacker killer
by sgifford (Prior) on Sep 08, 2003 at 22:00 UTC | |
by Joost (Canon) on Sep 10, 2003 at 10:39 UTC |