Quote:
Originally Posted by Paul M
We process e-mails in batches, plus as far as remember, attempts from a different IP address will trigger a seperate e-mail.
Its obvious its targeting each username from a wide range of IPs. If you have no interest in the e-mails, simply delete them.
|
I have no problems with the mails, I was just surprised that the 'locked' account is unlocked directly when the request comes from another ip. I did not know that before.
I have just tested it with one of my forums (3.8.7) and indeed the same happens. When I try to login from another ip, I have 5 more possibilities to use bruteforce hacking.
Perhaps it would be better to lock the account for 15 minutes without checking if the ip has changed. The successrate for a hacker is minimized then and a forum member normally will not change IP if he has typed the wrong password.
The only disadvantage of this is that some joker could stop a real member from logging-in if he continues to do this. So maybe that's the reason for unlocking from a new ip.