note 33403 added to function.sleep
| From: | cet at rack1 dot php dot net | Date: | Tue, 24 Jun 2003 23:10:13 +0000 |
| Subject: | note 33403 added to function.sleep | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-50967@lists.php.net to get a copy of this message | ||
About using sleep() after an authentication failure:
While it is true that crackers can launch multiple concurrent attempts, the number of concurrent
attempts is limited to your server's maximum number of concurrent requests. As this number is
usually miniscule in comparison to the numbers of attempts a cracker would probably need to brute
force a password, sleep() _does_ in fact provide effective anti-cracking benefit.
Of course, a smart cracker could write his code to end the connection long before the sleep() is
done, but that makes it a guessing game; how quickly can the connection be ended without accidently
losing the successful connections the cracker wants? This is not an easy question to answer for the
cracker because all of those concurrent connection attempts can significantly slow down all of the
responses, even successful ones. Against this "smart" cracker there is going to be a
limit; sleep(30) is probably going to be no more effective than sleep(5). In the end, using sleep()
makes the code neccessary to brute force a password much more complicated and that in itself will
eliminate some would-be crackers. For the others, it does slow them down somewhat.
So the short answer is that using sleep() after an authentication failure is _always_ better than
not using sleep().
Best of all is to use sleep() after successful authentication too-- this would mean that the cracker
_must_ wait the full sleep() period in every case and makes brute forcing a password require a very,
very long time (years?). This probably wouldn't even bother users that much as it would only
happen once per login.
----
Manual Page -- http://www.php.net/manual/en/function.sleep.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+33403
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+33403&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+33403&report=yes