Main author: Bernhard Fröhler
This is the component part of the Brute Force Stop Joomla! Extension package.
For detailed information, as well as instructions on how to download, install and configure Brute Force Stop, please browse to the bfstop wiki.
If you find any issues, please report them at the bfstop issue tracker.
If you are interested in the source code, or want to contribute, please check the bfstop source repository at github.
For any further questions, don't hesitate to contact me under bfstop@bfroehler.info
Version 2.0.0 migrates the component to PSR-4 namespaced classes
(Codeling\Component\Bfstop) and drops support for Joomla 3/4. Notable change
for integrators: the frontend router.php was removed, since all of its
build/parse logic was already commented out and effectively a no-op; Joomla's
default component router is used instead, with no change in behaviour.
BFStop's configuration was also consolidated into this component's Settings view (Components -> Brute Force Stop -> Settings). It used to be split between here and the plugin's own Options tab in the Plugin Manager; the plugin manifest no longer defines any configuration fields, so the component's Settings view is now the single place to configure BFStop (enabling/disabling the plugin itself still happens in the Plugin Manager, as with any Joomla plugin).
This version also adds adaptive, risk-based allowance of failed login attempts (issue #76): failed logins are now throttled per account across all source IPs combined (not just per IP), and an optional per-attempt risk score (known IP/username pairs, common usernames, missing User-Agent, GeoIP country, reverse-DNS) adjusts delay and block thresholds - see the plugin's CHANGELOG for the full list, and the new "Account-level Throttle", "GeoIP Database", and "Adaptive Risk Scoring" fieldsets in the Settings view. The "Information for IP Address" view (issue #169) also works again, using the same local GeoIP database instead of the discontinued freegeoip.net API it used to depend on.