I've been half banned

Discussion in 'Site Feedback/Bugs' started by clueless1, Sep 2, 2016.

  1. clueless1

    clueless1 member... yep, that's what I am:)

    Joined:
    Jan 8, 2008
    Messages:
    17,778
    Gender:
    Male
    Location:
    Here
    Ratings:
    +19,597
    I got half banned again. This time I got the prohibited ip address.

    94.197.120.245
     
    • Like Like x 2
    • Fat Controller

      Fat Controller 'Cuddly' Scottish Admin! Staff Member

      Joined:
      May 5, 2012
      Messages:
      27,742
      Gender:
      Male
      Occupation:
      Public Transport
      Location:
      At me 'puter, GCHQ Ashford Office, Middlesex
      Ratings:
      +52,149
      Top man! Thank you - I will go and clear it
       
      • Like Like x 2
      • Fat Controller

        Fat Controller 'Cuddly' Scottish Admin! Staff Member

        Joined:
        May 5, 2012
        Messages:
        27,742
        Gender:
        Male
        Occupation:
        Public Transport
        Location:
        At me 'puter, GCHQ Ashford Office, Middlesex
        Ratings:
        +52,149
        Done. Hopefully that will prevent it happening again
         
        • Like Like x 2
        • clueless1

          clueless1 member... yep, that's what I am:)

          Joined:
          Jan 8, 2008
          Messages:
          17,778
          Gender:
          Male
          Location:
          Here
          Ratings:
          +19,597
          I was thinking about how I'd tackle the problem admin face if I was in charge of software development.

          I suspect the viability of my proposed solution will depend on the availability of a suitable plugin, but here goes anyway.

          Quite simply, I'd set a time limit on ip based bans. I'd have the default settings at something like 12 hours. But instead of loading the site and reporting that the ip has been banned, which then tells a spammer to acquire a different ip and try again, I'd simply not serve a page, so that the site is down as far as that ip is concerned.

          Ideally, the ban duration could be set based on geography. UK bans for 12 hours, India, China and Russia (where quite honestly most cyber attacks come from) having a much longer default ban duration.

          I'd probably also, if I had total control over the code, implement something that says if the user on the banned ip is known to be legit, let them through but still ban anyone else on that ip. That way anyone with a current session cookie can get in anyway.

          There's probably flaws in my logic, but that's the route I'd initially go down if I were developing access control.
           
          • Like Like x 2
          Loading...

          Share This Page

          1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
            By continuing to use this site, you are consenting to our use of cookies.
            Dismiss Notice