Support

Admin Tools

#17836 Show users Failed login count

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Friday, 11 October 2013 14:43 CDT

user73471
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (None listed?)? Yes
Have I searched the tickets before posting? Yes
Have I read the documentation before posting (None listed?)?Yes
Joomla! version: (2.5.14)
PHP version: (5.4.17)
MySQL version: (5.5.32-cll)
Host: (Arvixe VPS)
Admin Tools version: (Current Stable 2.5.8 Pro)

Description of my issue:

I looked through your documentation and even googled Failed login count, display failed login count, count failed login attempts, failed attempts and so on. Would it be possible to notify the user that they have used 1 of # login attempts. and on # they will be banned for (time)? I have read a ton of forums that address this as something joomla should have standard but it seems to me that no one has published a fix/solution to this dilemma.

So would it be possible for adminpro to have that ability? If not is there a way to use admin pro to count the login attempts and display with a small edit?

Thank you very much

nicholas
Akeeba Staff
Manager
> Would it be possible to notify the user that they have used 1 of # login attempts. and on # they will be banned for (time)?

No and it's a good idea NOT to warn them. If you do you are giving out your configuration to attackers and they can now plan a slow, distributed attack which circumvents your protection. If they figure out that an IP is blocked after, let's say, 3 attempts in one minute they can use a botnet which tries up to two usernames every minute per IP. Since the botnet can have thousand of machines the attacker can keep brute forcing your site without triggering your protection. FYI this kind of attack has been going on since at least five years ago against SSH servers. Google "Hail Mary botnet" to get an idea of what I'm talking about.

So, the answer to your questions is no and no: No, it's not possible and no, we won't be adding this feature. This feature is unavailable by design and for security reasons.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!