Re: Securing http authentication from brute force attacks

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



From: James B. Byrne <byrnejb@xxxxxxxxxxxxx>
> We have several web applications deployed under Apache that require
> a user id / password authentication.  Some of these use htdigest and
> others use the application itself.
> 
> Recently we have experienced several brute force attacks against
> some of these services which have been dealt with for the nonce by
> changes to iptables.  However, I am not convinced that these changes
> are the answer.
> 
> Therefore I have been looking at http protection and have run across
> a few independently provided modules for Apache http security,
> mod_security being one of them.
> 
> I would like the opinion of other CentOS sysadmins who already have
> faced this same problem, with respect to the solutions available and
> those that they choose for themselves.

I did not test it but maybe check:
http://www.zdziarski.com/projects/mod_evasive/

JD


      
_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
http://lists.centos.org/mailman/listinfo/centos

[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux