|
|
Posted by Michael Daly on 04/09/07 18:46
antony wrote:
> but is so frequently that user have same ip?
> just enough to have same internet provider?
On the login page, create a hidden input field with a login count. When
you send back the invalid login, update the hidden count. Once you hit
the limit, write the page with a hidden "lockout" field.
The smart user will get around this with a complete page refresh, but
the dumb user will not.
Saving IPs will work if there is little time between logins - there
won't be enough time for a new IP to show up. If you're looking at
checking over more than one day, the IP is likely to change.
Mike
Navigation:
[Reply to this message]
|