http://www.heinleinsociety.org/thsnexus/

Login exceeded number of attempts
http://www.heinleinsociety.org/thsnexus/viewtopic.php?f=6&t=965
Page 1 of 1

Author:  ForumAdmin [ Thu Feb 03, 2011 7:40 am ]
Post subject:  Login exceeded number of attempts

Several people, including myself, have reported problems logging into the Forum.

I found this on the internet regarding phpBB3 Forums.
-----
A number of our members have reported receiving the "You exceeded the maximum number of login attempts" message while trying to login to the forum, and are then prompted to enter the confirmation code as well as their username and password.

Unfortunately it seems that several phpbb based forums have been attacked in the same manner which involves a bot persistently trying to login to member's accounts. The forum software catches this and after 3 attempts prompts with the challenge question.
There is no indication that the bot has ever got past this challenge (as it is specific to our forum) as it would require both the correct password, and the correct challenge answer.
Furthermore there is no indication that any accounts have been compromised by the bot correctly guessing a password in less than 3 attempts.

Sorry. in editing the post I lost the image
However, if you have a "weak" password, we would recommend that you change it to something that would be much more difficult for a bot to guess, using either a dictionary or brute force attack.
----

If this happens to you, look for a line further down the page as shown in the attachment below.
Answer this and you should be back to normal. Note that after you enter the answer to the question, you will have to re-enter either or both of the username and password before attempting to log in again.

Attachments:
Captcha.gif
Captcha.gif [ 5.33 KiB | Viewed 4965 times ]

Page 1 of 1 All times are UTC - 8 hours
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
http://www.phpbb.com/