Well, it's a stored MD5 hash in a database that checks from a php page with no login timeouts; from a security standpoint anything that can submit a form would be capable of breaking a login after some point.

That brings up a valid notation that I think we should have some sort of brute force detection; perhaps log every 10 requests a user makes under a ~20 second span...


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!