|
WebApp Sec
mailing list archives
Account Lockouts
From: Harrison Gladden <hgladden () gmail com>
Date: Wed, 1 Dec 2004 11:52:13 -0600
Hello all,
My question to the group is about handling account lock outs. Here's
the situation, assume there is a web interface that lets users log in
and do stuff, but the log-in process is constrained by the network
restrictions as well.. Meaning if a user tries to log in X times in Y
seconds and fails each time, then the account get locked out.
What are successfull techniques that could be used on the web
interface to avoid having a script run against it that would
potentially lock out 15000 user accounts, and create a headache for
the system administrators who have to manually unlock each account?
Also assume the current user account names are known by everyone.
Possible techniques we've thrown around:
1) Allow each user to pick their own username instead of using a
standard (i.e. First 3 letters of first name + Full last name)
2) Create a set time-out period for each account of X (maybe an hour)
Hopefully my question makes sense.
Thanks,
Harrison
--
___________________________________
Harrison Gladden <hgladden () gmail com>
Computer Engineer & Science Major
~Past experience: He who never makes
mistakes, never did anything that's worth.~
By Date
By Thread
Current thread:
- Account Lockouts Harrison Gladden (Dec 01)
|