The web server will quite happily let an IP call the same script 20,000 (or 20,000,000) times, as it doesn't have any way of telling the difference between a brute force attack and an application that just gets a lot of use. This is why the locking logic is built into the application, the application is the only point that knows the difference between a legitimate request and an invalid login attempt.
| We're not surrounded, we're in a target-rich environment! |
|---|
In reply to Re: Why do you have to worry about Brute Force Attacks?
by jasonk
in thread Why do you have to worry about Brute Force Attacks?
by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |