首页 \ 问答 \ 如何保护用户页面免受暴力攻击(How can I protect user pages from brute-force attack)

如何保护用户页面免受暴力攻击(How can I protect user pages from brute-force attack)

我想获得关于以下内容的建议:

使用jspTomcat上进行 网络应用程序 ,在这里用户输入登录名和密码后(两者都是自动定义的,在帐户创建后不会更改)能够进入他们的个人页面。

我想使用服务器上的ArrayList和用户的登录ID对用户帐户进行一些保护,其中一些登录ID的登录成功次数将保持不变(一段时间后线程创建量值为零)。

如果金额大于某个定义值 - 阻止登录(直到清除金额)并发送给用户电子邮件链接,在服务器内部单击将内部值设置为0后, 我会研究这个,但是我的问题是关于这种方法是否正确,以及这样的ArrayList将满足需求:

List<User> users = Collections.synchronizedList(userList);

并使用同步setget方法访问它。
其目的是为了抵御暴力攻击 (手动或者甚至是服务器驱动)。

有没有办法防范访问攻击(在短时间内进行许多登录尝试)?

提前致谢。


I'd like to get your advice about following:

I have web-application on Tomcat using jsp, where users after entering their login and password (both are defined automatically and not changed after account creation) are able to enter their personal page.

I want to make some protection for user accounts using ArrayList on server with users' login ids, where amount of not successful logins for some login ids will be hold (there will be thread making amount value zero after some time period).

In case amount is bigger than some defined value - block login (until amount cleaned) and send to user email link, after clicking on which amount value will be set to 0 internally in server. I will work on that, but my question is about if this approach is correct one and such ArrayList will satisfy needs:

List<User> users = Collections.synchronizedList(userList);

and access it using synchronized set and get methods.
The aim is to get protection against brute-force attacks (manual or maybe even server driven).

Is there a way to defend against access attacks (making many login attempts in short periods of time)?

Thanks in advance.


原文:https://stackoverflow.com/questions/34151920
更新时间:2023-05-02 11:05

最满意答案

.htaccess下行添加到.htaccess文件中

AddHandler application/x-httpd-php .do

这告诉服务器处理以.do结尾的所有文件为.php


Add the following line to your .htaccess file

AddHandler application/x-httpd-php .do

This tells the server to process all files ending with .do as .php.

相关问答

更多

相关文章

更多

最新问答

更多
  • 您如何使用git diff文件,并将其应用于同一存储库的副本的本地分支?(How do you take a git diff file, and apply it to a local branch that is a copy of the same repository?)
  • 将长浮点值剪切为2个小数点并复制到字符数组(Cut Long Float Value to 2 decimal points and copy to Character Array)
  • OctoberCMS侧边栏不呈现(OctoberCMS Sidebar not rendering)
  • 页面加载后对象是否有资格进行垃圾回收?(Are objects eligible for garbage collection after the page loads?)
  • codeigniter中的语言不能按预期工作(language in codeigniter doesn' t work as expected)
  • 在计算机拍照在哪里进入
  • 使用cin.get()从c ++中的输入流中丢弃不需要的字符(Using cin.get() to discard unwanted characters from the input stream in c++)
  • No for循环将在for循环中运行。(No for loop will run inside for loop. Testing for primes)
  • 单页应用程序:页面重新加载(Single Page Application: page reload)
  • 在循环中选择具有相似模式的列名称(Selecting Column Name With Similar Pattern in a Loop)
  • System.StackOverflow错误(System.StackOverflow error)
  • KnockoutJS未在嵌套模板上应用beforeRemove和afterAdd(KnockoutJS not applying beforeRemove and afterAdd on nested templates)
  • 散列包括方法和/或嵌套属性(Hash include methods and/or nested attributes)
  • android - 如何避免使用Samsung RFS文件系统延迟/冻结?(android - how to avoid lag/freezes with Samsung RFS filesystem?)
  • TensorFlow:基于索引列表创建新张量(TensorFlow: Create a new tensor based on list of indices)
  • 企业安全培训的各项内容
  • 错误:RPC失败;(error: RPC failed; curl transfer closed with outstanding read data remaining)
  • C#类名中允许哪些字符?(What characters are allowed in C# class name?)
  • NumPy:将int64值存储在np.array中并使用dtype float64并将其转换回整数是否安全?(NumPy: Is it safe to store an int64 value in an np.array with dtype float64 and later convert it back to integer?)
  • 注销后如何隐藏导航portlet?(How to hide navigation portlet after logout?)
  • 将多个行和可变行移动到列(moving multiple and variable rows to columns)
  • 提交表单时忽略基础href,而不使用Javascript(ignore base href when submitting form, without using Javascript)
  • 对setOnInfoWindowClickListener的意图(Intent on setOnInfoWindowClickListener)
  • Angular $资源不会改变方法(Angular $resource doesn't change method)
  • 在Angular 5中不是一个函数(is not a function in Angular 5)
  • 如何配置Composite C1以将.m和桌面作为同一站点提供服务(How to configure Composite C1 to serve .m and desktop as the same site)
  • 不适用:悬停在悬停时:在元素之前[复制](Don't apply :hover when hovering on :before element [duplicate])
  • 常见的python rpc和cli接口(Common python rpc and cli interface)
  • Mysql DB单个字段匹配多个其他字段(Mysql DB single field matching to multiple other fields)
  • 产品页面上的Magento Up出售对齐问题(Magento Up sell alignment issue on the products page)