Skip to Content Skip to Menu

🎃 Happy Halloween! Treat yourself with an awesome discount on memberships! Get 20% off now with code SPOOKY-2024!

Using CB AntiSpam for avoid brute force attack

  • dotcom22
  • dotcom22
  • OFFLINE
  • Posts: 522
  • Thanks: 14
  • Karma: 4
11 years 2 months ago #232259 by dotcom22
hello

I would like use CB AntiSpam only for one specific task. My goal would be to set the plugin for ban IP of the user who tried to login without success after for example 10 attempts (I don't want enable captcha for avoid to annoy users).

If I'm not wrong this is possible to be made with CB AntiSpam but I worry a bit to touch something who can result to ban normal users.

any clue ?

thank

I use Joomla 3.3.6 - CB 2.0.4 - CBSubs 4 - Several Incubator plugins

Please Log in or Create an account to join the conversation.

  • krileon
  • krileon
  • ONLINE
  • Posts: 48466
  • Thanks: 8280
  • Karma: 1443
11 years 2 months ago #232283 by krileon
Yes this is possible. Navigate to CB > Plugin Management > CB AntiSpam > Config > Login > Auto Block and configure it as follows.

Block: Enable
Attempts Limit: 10

The rest of the configuration is up to you. By default it only counts failed login attempts from the past month. Anything beyond that is discarded as brute force happens within a few seconds/minutes. It then blocks the IP for 1 hour (can configure this to whatever you like).


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in or Create an account to join the conversation.

  • dotcom22
  • dotcom22
  • OFFLINE
  • Posts: 522
  • Thanks: 14
  • Karma: 4
11 years 2 months ago #232503 by dotcom22
Replied by dotcom22 on topic Using CB AntiSpam for avoid brute force attack
hello

Well I used the setup described and all seem to be fine. I tried also to setup the "Forgot login" in same way but even after the amount of attempt set, I'm not blocked.

Any clue ?

I noticed also is possible to set Captcha in "Email form" but what is it ? CB have a contact form somewhere ? For what I seen, is not the default Joomla contact form...

I use Joomla 3.3.6 - CB 2.0.4 - CBSubs 4 - Several Incubator plugins

Please Log in or Create an account to join the conversation.

  • krileon
  • krileon
  • ONLINE
  • Posts: 48466
  • Thanks: 8280
  • Karma: 1443
11 years 2 months ago #232526 by krileon

Well I used the setup described and all seem to be fine. I tried also to setup the "Forgot login" in same way but even after the amount of attempt set, I'm not blocked.

You can't block CB Moderators. Ensure you're testing with a standard user, etc.. or not logged in (note if it finds the IP belongs to an admin it will ignore the block). Check "Blocks" in backend to see if the block took affect. Also note for Forgot Login it has to be a valid use. For example if you're trying to test it against a user that does not exist it does not log it as an attempt. Attempts are also purged on login. So to cause a block you'd need to request forgot login on a user that exists say 5 times in a row without logging into that user to clear them.

noticed also is possible to set Captcha in "Email form" but what is it ? CB have a contact form somewhere ? For what I seen, is not the default Joomla contact form...

Email Form is the form provided to allow users to email other users directly on your site. You should have a menu item for it on CB Menu or a link to click from the Email field on users profiles (other than your own). If not you may have disabled the fields display or disabled the email form in CB > Configuration > General.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in or Create an account to join the conversation.

Moderators: beatnantkrileon
Powered by Kunena Forum