Brute Force Attack thwart... idea

Do you have an idea for the Joomla community that you can help implement? Discuss in here.
Locked
RonC3331
Joomla! Apprentice
Joomla! Apprentice
Posts: 22
Joined: Thu Oct 15, 2009 9:47 pm

Brute Force Attack thwart... idea

Post by RonC3331 » Sun Jan 19, 2014 8:47 pm

I have many Joomla site and they are under constant brute force attacks. I have deployed a few different measures to protect the sites. The problem as most know is the ability of the attacker to keep using different IP addresses, so there is no easy way to stop them. This type of attack seems to be escalating...

To me the issue could be minimized if there was a unique path for the admin folder for every installation. I realize this would not work for the front end login though. Randomizing the backend login path though would throw a big wrench into systematic automated attacks. Maybe this would too hard to create but I just thought I would put it out there...

User avatar
pe7er
Joomla! Master
Joomla! Master
Posts: 24977
Joined: Thu Aug 18, 2005 8:55 pm
Location: Nijmegen, Netherlands
Contact:

Re: Brute Force Attack thwart... idea

Post by pe7er » Mon Jan 20, 2014 6:45 am

RonC3331 wrote:To me the issue could be minimized if there was a unique path for the admin folder for every installation. I realize this would not work for the front end login though. Randomizing the backend login path though would throw a big wrench into systematic automated attacks. Maybe this would too hard to create but I just thought I would put it out there...
Nice idea, but it's already very easy to create such random back-end login paths:
by using a 3rd party extension you can extend the back-end login with a security token
If people try to access /administrator without ?secret-token-defined-by-you they will be redirected to your homepage.
http://extensions.joomla.org/extensions ... protection

To extra secure the front-end, you can use Two Factor Authentication (since Joomla 3.2).
Kind Regards,
Peter Martin, Global Moderator
Company website: https://db8.nl/en/ - Joomla specialist, Nijmegen, Netherlands
The best website: https://the-best-website.com

User avatar
muzaru
Joomla! Explorer
Joomla! Explorer
Posts: 279
Joined: Wed Mar 31, 2010 9:34 am
Location: Amersfoort

Re: Brute Force Attack thwart... idea

Post by muzaru » Mon Jan 20, 2014 8:00 am

What I often do is create a htaccess (in de admin folder), which blocks all but mine and a few select ip's. This is doable for me because there's never more than 5 different users on my clients backend :)

SpringJS
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Fri Jul 25, 2014 8:53 am
Contact:

Re: Brute Force Attack thwart... idea

Post by SpringJS » Fri Jul 25, 2014 9:09 am

I think that could be amazing too
Last edited by alikon on Thu Jul 31, 2014 5:13 am, edited 2 times in total.
Reason: removed manual signature

FlashRebel

Re: Brute Force Attack thwart... idea

Post by FlashRebel » Sun Jul 27, 2014 10:42 am

Personaly I use password for admin area using .htaccess for in admin folder and have never problem. I use it how Admin tools from Akeba create it, dont use that component, just that admin password. It works well for me.


Locked

Return to “Joomla! Ideas Forum”