Re: best way to limit # of attempts to login to protected page?
This WebDNA talk-list message is from 2000
It keeps the original formatting.
numero = 35446
interpreted = N
texte = You mean to say if someone fails, say in 3 attempts to login, you would wantthem toget a new password and/or username? In that case you can do the number checkas wellas the IPAddress, or you can limit 3 attempts in a day/IPaddress, etc..I really don't know any other way to do this.anup> I also am not sure, but assume like you that a formvar overrides anURL-passed value.> but even if so, then the would-be-hacker could simply view source code,see the> incrementing formvar, and realize he could simply load the login form pagefresh to> reset the counter...>> Anup Setty wrote:>> > I pass the counter value as a formvariable, i.e., when I check for the> > username and password,> > and if it is wrong, I redirect them to the login page via auto formsubmit.> > I think the formvariable> > overrides the value passed through the URL, I'm not sure, you have agood> > point there, I will have> > to go back and do a test on that,> >> > anup>>> -------------------------------------------------------------> This message is sent to you because you are subscribed to> the mailing list
.> To unsubscribe, E-mail to: > To switch to the DIGEST mode, E-mail to> Web Archive of this list is at: http://search.smithmicro.com/-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://search.smithmicro.com/
Associated Messages, from the most recent to the oldest:
You mean to say if someone fails, say in 3 attempts to login, you would wantthem toget a new password and/or username? In that case you can do the number checkas wellas the IPAddress, or you can limit 3 attempts in a day/IPaddress, etc..I really don't know any other way to do this.anup> I also am not sure, but assume like you that a formvar overrides anURL-passed value.> but even if so, then the would-be-hacker could simply view source code,see the> incrementing formvar, and realize he could simply load the login form pagefresh to> reset the counter...>> Anup Setty wrote:>> > I pass the counter value as a formvariable, i.e., when I check for the> > username and password,> > and if it is wrong, I redirect them to the login page via auto formsubmit.> > I think the formvariable> > overrides the value passed through the URL, I'm not sure, you have agood> > point there, I will have> > to go back and do a test on that,> >> > anup>>> -------------------------------------------------------------> This message is sent to you because you are subscribed to> the mailing list .> To unsubscribe, E-mail to: > To switch to the DIGEST mode, E-mail to> Web Archive of this list is at: http://search.smithmicro.com/-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://search.smithmicro.com/
Anup Setty
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
random images (1997)
Web Delivery Page concept (1997)
Writing [raw] to a file (2000)
[OT] For Mac Users (1999)
Email encryption (1998)
[WebDNA] .debug file (2009)
Re1000001: Setting up shop (1997)
[WebDNA] Authorize.net and [tcpconnect] (2016)
quotes and truncating? (1997)
Dumb Question about Docs (1997)
WebCatb15 Mac CGI -- [purchase] (1997)
WebCatalog can't find database (1997)
Protect vs Authenicate (1997)
PIXO (1997)
Summing a field full of numbers ... (1997)
Help with Shipping Costs (1997)
Re:quit command on NT (1997)
Frames and WebCat (1997)
Webcatalog error, Plug-in for Webstar (1996)
Multiple Passwords (1997)