Skip to Main Content
ADG Product Ideas
Status Will not implement
Categories System wide feature
Created by Guest
Created on Mar 4, 2024

Security Feature to lockout IPs that spam logins

ADG is severely lacking in security features. There needs to be some sort of setting that will block an IP address for an hour or so if they attempt login more than 20 times (with bad passwords). Our webserver is getting spammed with login attempts

  • Attach files
  • Admin
    Cale Schweitz
    Reply
    |
    Apr 12, 2024

    DOS (Denial Of Service) type attacks are better handled at a firewall level. Whilst we could certainly lock out users on an IP based value, there is no saving on resources, because we still have to do a database lookup in order to determine if the IP address is on a blacklist or not. Modern firewalls can automatically add IP addresses to blacklists.

  • Admin
    Cale Schweitz
    Reply
    |
    Mar 6, 2024

    I am forwarding this to development for review.