Max Retries and Lockouts and Times not working as expected
-
I’m using Loginizer 1.7.9 with the following Brute Force settings:
Max Retries 3, Lockout Time 15 minutes, Max Lockouts 2, Extend Lockout 24 hours, Reset Retries 24 hours. Email Notification after 2 lockouts.I received 3 emails (with corresponding log entries for the same IP address within 4 hours. Showing:
9 failed login attempts and 3 lockout(s) from IP 5.188.62.21 on your site :
https://xxxxx.xxx
Last Login Attempt : 19/May/2023 16:56:44 +00:00
Last User Attempt : admin
IP has been blocked until : 20/May/2023 16:56:44 +00:008 failed login attempts and 2 lockout(s) from IP 5.188.62.21 on your site :
https://xxxxx.xxx
Last Login Attempt : 19/May/2023 15:13:50 +00:00
Last User Attempt : admin
IP has been blocked until : 20/May/2023 15:13:50 +00:007 failed login attempts and 2 lockout(s) from IP 5.188.62.21 on your site :
https://xxxxx.xxx
Last Login Attempt : 19/May/2023 13:31:49 +00:00
Last User Attempt : admin
IP has been blocked until : 20/May/2023 13:31:49 +00:00Questions:
1. If the Max Retries is 3 and Max Lockouts is 2, why is there 9 failed login attempts and 3 lockouts within the same period?
2. If the Extend(ed) lockout time is 24 hours, how is it that this IP could attempt another 2 logins within a 4 hour period all during the extended lockout period?Am I misunderstanding how Loginizer works or is something amiss?
Thanks.
The page I need help with: [log in to see the link]
- The topic ‘Max Retries and Lockouts and Times not working as expected’ is closed to new replies.