My thinking is I'm getting waves of brute force attacks against member accounts that still persist past the VB strikes system, after blocking China etc in Apache and installing an anti-proxy mod. I'm guessing the hacking programs are just passing random values directly to login.php so I wondered if popping in some form of Captcha that needed to be satisfied before you could talk to login.php might slow the attacks down. For instance I use Q&A HVM on my registrations that has worked well for much time but it would be nice to apply that to accessing login.php as well.
|