-
Website
http://www.matasano.com/log -
Original page
http://www.matasano.com/log/1342/my-pentest-secret-password-guessing/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Press Controls
3 comments · 2 points
-
ChrisMtso
12 comments · 1 points
-
Eric Monti
11 comments · 1 points
-
StatlerAndWaldorf
12 comments · 3 points
-
Dave G.
7 comments · 1 points
-
-
Popular Threads
You definitely have to do the same thing for both valid and invalid attempts, otherwise it creates a side channel as Dave mentions in a comment above.
I think the Unix /bin/login program solved all of these a long time ago. That is, unless you have a wtmp smasher! Elite!
Great. Now I need a fancy avatar. Thanks for making me get all web 1.5.
Even with that info leak, this seems a very good way to deal with distributed brute-forcing, because it is no longer concerned with source IP.
Thanks for this idea, Dave. Do you know if such a thing has been implemented for PAM? That way individual daemons need not be modified.
But my question was aimed at, if a valid username/password combination is used, are they still subject to a delay before authentication. I suppose the obvious answer is yes, but I was just wondering if this was the original proposal.
I am sure it's not perfect, but I like it better than a lot of the alternatives.
As always, depends on how much security you want versus how much you want to annoy your users.
I've just been thinking about it more, perhaps the correct solution is to use random login delays (with a lower and upper limit in timeout) for both valid and failed attempts, and as such like one of the other commenters had mentioned a 1 or 2 second delay can slow down a paralellized brute force attack quite effectively.
still our friend...
:D
Are we still there...? Login / Password...? And I thought I was in a Hollywood screen set!! dang!
//DG