Solved

Limit web interface login attempts

Posted on 2011-09-02
8
1,029 Views
Last Modified: 2012-05-12
due to SAS 70 audit requirements i must enforce an attempted login limit on my web interface, which runs on the same box as the secure gateway.   W2k3 on IIS6.  WI 4.0.  SG 3.0.  Get me pointed in the right direction?
0
Comment
Question by:alexsupertramp
  • 4
  • 3
8 Comments
 
LVL 11

Expert Comment

by:KrAzY
Comment Utility
Limit as in the amount of times they can log in in a certain amount of seconds/minutes or amount of login attempts and then lockout?  Does SAS have those limitations built in?  Usually you should look to your application to provide restrictions and not your Web Interface.
0
 
LVL 4

Author Comment

by:alexsupertramp
Comment Utility
sorry, i wasn't specific enough: i need to limit the amount of incorrect login attempts at the web interface login.
0
 
LVL 11

Expert Comment

by:KrAzY
Comment Utility
Does Active Directory "Login Attempts" satisfy this?
0
 
LVL 4

Author Comment

by:alexsupertramp
Comment Utility
where is there a "login attempts" option in ad?
0
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

 
LVL 11

Accepted Solution

by:
KrAzY earned 250 total points
Comment Utility
0
 
LVL 4

Author Comment

by:alexsupertramp
Comment Utility
Thanks, I found this yesterday, and it's good info, but from testing i've done i don't think it's effective at the web interface login level.  
0
 
LVL 23

Assisted Solution

by:Dirk Kotte
Dirk Kotte earned 250 total points
Comment Utility
for comliance we use two factor authentication fron aladdin / safenet.
this solution (safeword) has build-in attack logging and protection.
 
0
 
LVL 4

Author Closing Comment

by:alexsupertramp
Comment Utility
Thanks for the valuable info.  Both solutions will be helpful.
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Several part series to implement Internet Explorer 11 Enterprise Mode
Resolve DNS query failed errors for Exchange
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now