Login restriction question

Status
Not open for further replies.

Dave Bolt

Cadet
Joined
Nov 13, 2013
Messages
1
I want to restrict user logins as a result of brute force attacks.
Currently I can find a list of users quite easily with metasploit, which means I could easily start trying to access the CIFS shares by just trying combinations until I find a password that works.
FreeBSD allows me to put a delay into the login on failed attempts, and a lockout after a number of failed attempts, but my attempts to add these settings are currently being reset when FreeNAS is rebooted and in any case don't seem to be having any effect.
I have not found any provision in Samba to add these features.
Can someone either point me at the right thread or tell me the right question to ask. I'm not getting very far at the moment.
Thanks
 

pirateghost

Unintelligible Geek
Joined
Feb 29, 2012
Messages
4,219
Brute force attacks on your LAN? You need to straighten out your network policies with your users, not try and mitigate it on the device.

Sent from my Nexus 5
 

cyberjock

Inactive Account
Joined
Mar 25, 2012
Messages
19,526
Brute force attacks on your LAN? You need to straighten out your network policies with your users, not try and mitigate it on the device.

Sent from my Nexus 5

No kidding! If you are dealing with those problems you have FAR FAR bigger problems than a few settings to configure on FreeNAS.
 
Status
Not open for further replies.
Top