• Welcome to Valhalla Legends Archive.
 

Password lag restriction

Started by Tazo, December 18, 2005, 08:39 PM

Previous topic - Next topic

Tazo

I'm not sure what the name for it is, but I mean when you try too many wrong passwords in a set amount of time, you will get locked out of logging in period from that server for a set (?) amount of time..for instance, if i try to logon an account 4 times in 10 seconds, i will be banned (locked out, w/e) for 1 hour..has anyone researched this and can provide me with accurate information?

Yegg


Tazo

Not really, its different than an IP ban..  ::)

Networks

Does it temporarily lock the account for a set amount of time or does it just lock YOU out (being an IPBan). I'd say that's an interesting exploit to use against those that you hate. Continually locking them out of an account until it expires and then registering it yourself....I think I said to much........=P

Ringo

yep, if you try to many 0x3A/0x29's, bnet will put a lock on the account in question, and lock your IP, meaning the server just wont respond to account logons.
If you changed IP, you will ntoice you get 1 shot at logging on the account, if you type in a wrong password, it then puts a logon lock on ur IP again.
I think the lock on the account lasts an hour, and IP locks last 30mins, but im not 100% sure

Tazo

#5
any idea what you need to do (how many tries) to get locked? or is it just like 5 misses in a row

EDIT: This is via CHAT connection, not binary!!

Edit: wow, you get locked out fast..with 10 sec delays, i got fuked over after 3 tries

[23:36:59] Joe:aback
[23:36:59] Login incorrect.
[23:37:09] Joe:abandoned
[23:37:10] Login incorrect.
[23:37:20] Joe:abandonment
[23:37:20] Login incorrect.
[23:37:30] Joe:abashed
[23:39:32] 2000 NULL


Ringo: switching IPs offers you 3 more fresh logons~

Okay, increased my delay to 1 minute-and still locked from that IP. I have come to the conclusion that 3 failed password attempts on 1 account via chat connection will lock that IP out of logging in for 1 hour. However, battle.net doesnt terminate the connection, just sends NULL packets every 2 minutes.

Explicit

Doesn't Battle.net just lock the account you're trying to log onto, rather than IP ban you overall?
I'm awake in the infinite cold.

[13:41:45]<@Fapiko> Why is TehUser asking for wang pictures?
[13:42:03]<@TehUser> I wasn't asking for wang pictures, I was looking at them.
[13:47:40]<@TehUser> Mine's fairly short.

Warrior

Quote from: effect on March 09, 2006, 11:52 PM
Islam is a steaming pile of fucking dog shit. Everything about it is flawed, anybody who believes in it is a terrorist, if you disagree with me, then im sorry your wrong.

Quote from: Rule on May 07, 2006, 01:30 PM
Why don't you stop being American and start acting like a decent human?

Eric

#8
Battle.net will restrict the login of an account after 4 failed login attempts.  The restriction is based on IP and usually lasts about 15 minutes on a first offence (rumored to double each time the limit is reached).  In addition to locking you out of the account, the restriction limits the number of failed logins you can get on other accounts to 1.  Bruteforce or dictionary-based cracking attempts will most likely fail due to these restrictions.

LordNevar

Quote from: Lord[nK] on December 19, 2005, 05:54 AM
Battle.net will restrict the login of an account after 4 failed login attempts.  The restriction is based on IP and usually lasts about 15 minutes on a first offence (rumored to double each time the limit is reached).  In addition to locking you out of the account, the restriction limits the number of failed logins you can get on other accounts to 1.  Bruteforce or dictionary-based cracking attempts will most likely fail due to these restrictions.

This information is correct. There is no way to bypass this in any fashion as it is a server side check. This information is not stored locally.

A good fortune may forbode a bad luck, which may in turn disguise a good fortune.
The greatest trick the Devil ever pulled, was convincing the world he didn't exsist.

Tazo

Quote from: Lord[nK] on December 19, 2005, 05:54 AM
Battle.net will restrict the login of an account after 4 failed login attempts.  The restriction is based on IP and usually lasts about 15 minutes on a first offence (rumored to double each time the limit is reached).  In addition to locking you out of the account, the restriction limits the number of failed logins you can get on other accounts to 1.  Bruteforce or dictionary-based cracking attempts will most likely fail due to these restrictions.
Does this apply to CHAT and Binary connections, or just CHAT?

l2k-Shadow

Quote from: Tazo on December 19, 2005, 02:05 PM
Quote from: Lord[nK] on December 19, 2005, 05:54 AM
Battle.net will restrict the login of an account after 4 failed login attempts.  The restriction is based on IP and usually lasts about 15 minutes on a first offence (rumored to double each time the limit is reached).  In addition to locking you out of the account, the restriction limits the number of failed logins you can get on other accounts to 1.  Bruteforce or dictionary-based cracking attempts will most likely fail due to these restrictions.
Does this apply to CHAT and Binary connections, or just CHAT?
Both.
Quote from: replaced on November 04, 2006, 11:54 AM
I dunno wat it means, someone tell me whats ix86 and pmac?
Can someone send me a working bot source (with bnls support) to my email?  Then help me copy and paste it to my bot? ;D
Já jsem byl určenej abych tady žil,
Dával si ovar, křen a k tomu pivo pil.
Tam by ses povídaj jak prase v žitě měl,
Já nechci před nikym sednout si na prdel.

Já nejsem z USA, já nejsem z USA, já vážně nejsem z USA... a snad se proto na mě nezloběj.