Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] Secure OWA |
|---|---|
| Date: | Wed, 30 Aug 2006 16:14:40 -0400 |
I think a possibly better approach, although it doesn't seem like you could implement it quite as simply as account lockouts, would be to lock out, not the account, but the originating IP address, for a duration.
Ever since I read this thread (http://vegan.net/lb/archive/08-2004/0118.html) on one of the load-balancer discussion lists I've been skeptical of using IP addresses for much of anything. My guess is that if you do things like ban IPs automatically you run the risk of accidentally locking out thousands of legit users as well as the one who is misbehaving.
A few of the more interesting comments in the thread:
"...myriad of enterprise networks that load-balance outbound client connections across proxy servers which are connected to different ISPs, with totally different source IP..."
"...The AOL client does a split tunnel type thing, where the HTTP gets tunneled through the UDP conversation to AOL's network and back out the proxies to the Internet, but the HTTPS (and other stuff) goes directly from client to server..."
Regards, Brian
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-disclosure] NT4 worm, Juha-Matti Laurio |
|---|---|
| Next by Date: | Re: [Full-disclosure] NT4 worm, Juha-Matti Laurio |
| Previous by Thread: | Re: [Full-disclosure] Secure OWA, Mark Senior |
| Next by Thread: | RE: [Full-disclosure] Secure OWA, Renshaw, Rick \(C.\) |
| Indexes: | [Date] [Thread] [Top] [All Lists] |