LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Install/Configuration > How to prevent against htpasswd brute force?

Reply
 
Thread Tools Display Modes
  #1  
Old 11-03-2007, 10:04 PM
matty matty is offline
New Member
 
Join Date: Nov 2007
Posts: 1
Default How to prevent against htpasswd brute force?

Hi, im running a website mainly for my own use, testing etc, however i have some parts protected by htpasswd, ive tried setting maximum requests/second to 5 on the server level, but if i hold down enter on the password prompt it pops up about 20 times per second with no blocking.

How would i go about protecting my site password protected areas from brute force/ or exploits?

Thanks
Reply With Quote
  #2  
Old 11-04-2007, 03:51 AM
brrr brrr is offline
Senior Member
 
Join Date: Aug 2007
Posts: 94
Perhaps have a look at using something like fail2ban. A guide to using it is here:

http://www.howtoforge.com/fail2ban_debian_etch

or BFD, esp if you use the APF firewall...
http://www.rfxnetworks.com/downloads/bfd-current.tar.gz

Unless I am mistaken, I don't think there is anything internal that Litespeed can do to prevent brute force attacks against HTTP basic authentication. Although it would certainly be a good feature to have...

Last edited by brrr; 11-04-2007 at 04:16 AM..
Reply With Quote
  #3  
Old 04-17-2008, 06:40 PM
anewday anewday is offline
Senior Member
 
Join Date: Nov 2007
Location: New York
Posts: 723
Use CSF, it has lfd to block it.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 05:04 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.