note 28912 deleted from function.sleep by danbrown
| From: | danbrown@php.net | Date: | Sat, 14 Mar 2009 14:39:19 +0000 |
| Subject: | note 28912 deleted from function.sleep by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-151885@lists.php.net to get a copy of this message | ||
Note Submitter: josh at NO chatgris SPAM dot com
----
Contrary to previous posts, sleep provides not security whatsoever against crackers. They can quite
easily create a multithreaded program that will try 1000 passwords at a time effectively disabling
your sleep pause, and sessions don't help as each a request can make itself look like a new
session. The only way to make this effective at all is to store the last time a user attempted to
login in a database and onyl allow x tries per time period.