Idea sandbox Idea sandbox
Popular ideas Popular ideas
Ideas in development Ideas in development
Implemented ideas Implemented ideas
Idea #119: Missing admin interface brute force protection

Written by iboguev the 15 Mar 10 at 07:41. Related project: 1.x all. Status: New
Rationale
Hi,

I am using LimeSurvey to capture and store some relatively sensitive/interesting data. I am a bit concerned that the application doesn't provide (as far as I am aware) any built in features that will discourage potential admin login brute force attacks.
Tags: Security

1
votes
up equal down
Solution #1: Security Enhancement - admin interface brute force protection
Written by iboguev the 15 Mar 10 at 07:41.
It would be great if some sort of brute force admin interface password guessing prevention mechanism is put in place. Examples of it would be to have the attacked account locked out for X minutes after a number of failed authentication attempts are detected.

Or the authentication process can be automatically delayed with XX seconds if a brute force attack is detected. This will be enough to slowdown an attacker to a level where the brute force attack would not be feasible. This can be combined with password complexity rules and will have minimal user impact.

An additional feature can be to send an email alert to the admin if brute force attack is detected.

Propose your solution


Duplicates


Comments
No comments.

Post your comment