Quantcast
Channel: Adobe Community: Message List - ColdFusion
Viewing all articles
Browse latest Browse all 21760

Re: How to best count failed login attempts

$
0
0

Two other things I just remembered, only send your "someone is hacking" email once or twice at a specific counts. You don't want to fill someone's email inbox with hundreds or thousands of automated attack email alerts.

 

Also for us, our users supply an account number, user name and password. For slightly better security we opted to not give detailed info of what failed. Instead we return a generic "invalid account number, user name or password."


Viewing all articles
Browse latest Browse all 21760

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>