note 33403 added to function.sleep

From: Date: Tue, 24 Jun 2003 23:10:13 +0000
Subject: note 33403 added to function.sleep
Groups: php.notes 
Request: Send a blank email to php-notes+get-50967@lists.php.net to get a copy of this message
About using sleep() after an authentication failure: While it is true that crackers can launch multiple concurrent attempts, the number of concurrent attempts is limited to your server's maximum number of concurrent requests. As this number is usually miniscule in comparison to the numbers of attempts a cracker would probably need to brute force a password, sleep() _does_ in fact provide effective anti-cracking benefit. Of course, a smart cracker could write his code to end the connection long before the sleep() is done, but that makes it a guessing game; how quickly can the connection be ended without accidently losing the successful connections the cracker wants? This is not an easy question to answer for the cracker because all of those concurrent connection attempts can significantly slow down all of the responses, even successful ones. Against this "smart" cracker there is going to be a limit; sleep(30) is probably going to be no more effective than sleep(5). In the end, using sleep() makes the code neccessary to brute force a password much more complicated and that in itself will eliminate some would-be crackers. For the others, it does slow them down somewhat. So the short answer is that using sleep() after an authentication failure is _always_ better than not using sleep(). Best of all is to use sleep() after successful authentication too-- this would mean that the cracker _must_ wait the full sleep() period in every case and makes brute forcing a password require a very, very long time (years?). This probably wouldn't even bother users that much as it would only happen once per login. ---- Manual Page -- http://www.php.net/manual/en/function.sleep.php Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+33403 Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+33403&report=yes Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+33403&report=yes

« previous php.notes (#50967) next »