Skip to content

Latest commit

 

History

308 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

com_bfstop

Brute Force Stop Joomla! Component

Main author: Bernhard Fröhler

This is the component part of the Brute Force Stop Joomla! Extension package.

For detailed information, as well as instructions on how to download, install and configure Brute Force Stop, please browse to the bfstop wiki.

If you find any issues, please report them at the bfstop issue tracker.

If you are interested in the source code, or want to contribute, please check the bfstop source repository at github.

For any further questions, don't hesitate to contact me under bfstop@bfroehler.info

2.0.0: Joomla 5/6 migration

Version 2.0.0 migrates the component to PSR-4 namespaced classes (Codeling\Component\Bfstop) and drops support for Joomla 3/4. Notable change for integrators: the frontend router.php was removed, since all of its build/parse logic was already commented out and effectively a no-op; Joomla's default component router is used instead, with no change in behaviour.

BFStop's configuration was also consolidated into this component's Settings view (Components -> Brute Force Stop -> Settings). It used to be split between here and the plugin's own Options tab in the Plugin Manager; the plugin manifest no longer defines any configuration fields, so the component's Settings view is now the single place to configure BFStop (enabling/disabling the plugin itself still happens in the Plugin Manager, as with any Joomla plugin).

This version also adds adaptive, risk-based allowance of failed login attempts (issue #76): failed logins are now throttled per account across all source IPs combined (not just per IP), and an optional per-attempt risk score (known IP/username pairs, common usernames, missing User-Agent, GeoIP country, reverse-DNS) adjusts delay and block thresholds - see the plugin's CHANGELOG for the full list, and the new "Account-level Throttle", "GeoIP Database", and "Adaptive Risk Scoring" fieldsets in the Settings view. The "Information for IP Address" view (issue #169) also works again, using the same local GeoIP database instead of the discontinued freegeoip.net API it used to depend on.

About

Brute Force Stop Component (for Joomla!)

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages