PCI Compliance Scanning & SAQ
Making compliance easy...

Sign up now and get your SAQ compliance certificate online quickly and easily for your merchant bank.Sign up now for both the SAQ Compliance certificate and your PCI Scan Compliance certificate.

PCI SAQ Wizard

pci scanning

Our PCI Tools are from approved PCI scanning vendors and approved PCI Quality Security Assessors!

How to Prevent Brute Force Attacks?


What is a brute force attack? No, it has nothing to do with physical aggression. Rather, it is a technique utilised by internet criminals and hackers to gain access to encrypted data. These sorry reprobates rely on this method to gain access to confidential information, specifically credit card data.

How can a website block them? The software that hackers use to gain access to your system is really quite simple. Basically, it will continue to guess random passwords and usernames until it cracks the codes. If they do manage to identify your codes and gain access, hackers will be able to review sensitive information such as email and FTP accounts.

The technique is called brute force because they are essentially forcing their way into your system after hundreds, even thousands of attempts. The dreaded dictionary based attacks rely on automated scripts and can guess thousands of common usernames each hour.

There are also generated logins, which is a program that creates random usernames and passwords until the code has been cracked. Of course, these programs do not always work, but if you ignore the signs it is far more likely that a hacker will gain entry.

One sure-fire way to detect a brute force attempt is by accessing the log files on your server. If you discover dozens, hundreds or even thousands of failed login attempts, it is sure sign that someone is trying to illegally gain access to your system.

Okay, but how do you actually prevent an attack? For starters, you should restrict the number of login attempts. Really, there is no reason why anyone would need more than one or two attempts. And if they have forgotten their password or username, they can always request a new one. It is also a good idea to ban all users that have consistently recorded multiple failed login attempts. Ninety-nine times out of a hundred these users are actually hackers.