3 ms·
We do have fail to ban type logic in place. The attacker used a botnet; requests came in from many different IP addresses.
by methodover 9y ago
We do have fail to ban type logic in place. The attacker used a botnet; requests came in from many different IP addresses.
- greenyouse 9y agoHave you tried rate limiting based on the user account? That should block a distributed attack since each login would count against the rate limit independent of the IP address.
- ScottBurson 9y agoHow would that help in this situation? The attacker had a database of user/password pairs they were trying; they weren't trying to brute-force a particular account.
- greenyouse 9y agoOops, you're completely correct. I was thinking of the brute force scenario.