Page 1 of 1

Protection from malicious login attempts to web interface

Posted: July 21st, 2013, 3:33 pm
by milhausnixon
Over the last few days, I've noticed a huge spike in invalid login attempts from various IPs, mostly from China but a few business ISPs in the US. They will try to login for an hour or two at the rate of 3-4 per second. Other than changing the port (which I did) or specifically blocking the offending IPs with iptables (which won't work as it's from many different sources) is there any functionality in sabnzbd to limit the number of logins before blocking/banning an IP address? I don't want to do a whitelist because I'll access the interface from various locations.

Re: Protection from malicious login attempts to web interfac

Posted: July 21st, 2013, 4:21 pm
by shypike
Using a non-standard port is recommended.
We haven't planned any additional facilities.