Limiting user login attempts in PHP

后端 未结 8 1499
既然无缘
既然无缘 2020-12-03 19:13

I\'ve seen web apps with limitations for user login attempts.

Is it a security necessity and, if so, why?

For example: you had three failed login att

8条回答
  •  我在风中等你
    2020-12-03 19:38

    I reckon putting a 'failed attempts' counter in the DB would be the safest and easiest way to go. That way the user can't bypass it (by disabling cookies). Reset on successful login of course.

    You can count by IP and/or by username. Advantage of IP is that you can block one person trying to hack multiple accounts. If you count by username you can block people using a server farm and won't accidentally throttle people on the same network.

提交回复
热议问题