Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 28 May 1999 12:40:35 +1000 (EST)
From:      Nicholas Brawn <ncb@zip.com.au>
To:        "Brian W. Buchanan" <brian@CSUA.Berkeley.EDU>
Cc:        freebsd-security@FreeBSD.ORG
Subject:   Re: Locking out accounts after repeated failures
Message-ID:  <Pine.LNX.4.05.9905281238550.6310-100000@zipper.zip.com.au>
In-Reply-To: <Pine.BSF.4.05.9905271934170.3578-100000@smarter.than.nu>

next in thread | previous in thread | raw e-mail | index | archive | help
Yes. I'm interested in doing it on a bastion host and servers connected to
public networks (ie, Internet). Of course the root account would not be
locked out, but then you couldn't log in as root except at console.

Nick

On Thu, 27 May 1999, Brian W. Buchanan wrote:

> On Fri, 28 May 1999, Nicholas Brawn wrote:
> 
> > I'm interested to know if freebsd has the capability to lock out users
> > after 5 consecutive bad login attempts, with the "counter" being cleared
> > after each successful login. If it is capable, could someone please point
> > me to the right documentation/files.
> 
> Are you sure you want to do this?  This leads to a very obvious denial of
> service attack.
> 
> -- 
> Brian Buchanan                                     brian@CSUA.Berkeley.EDU
> --------------------------------------------------------------------------
> FreeBSD - The Power to Serve!                       http://www.freebsd.org
> 
> daemon(n): 1. an attendant power or spirit : GENIUS
>            2. the cute little mascot of the FreeBSD operating system
> 



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.LNX.4.05.9905281238550.6310-100000>