Basic authentication - maximum allowed attempts

Use this forum to discuss possible implementation of a new feature before opening a ticket.
A developer shall edit the topic title with "[xxx]" where xxx is the id of the accompanying tracker id.
Duplicate posts about the same id. +1 posts are not allowed.

Moderators: leecollings, remb0

Post Reply
garp
Posts: 7
Joined: Monday 30 September 2013 18:43
Target OS: Raspberry Pi / ODroid
Domoticz version:
Contact:

Basic authentication - maximum allowed attempts

Post by garp »

I've set up a reverse proxy in my DMZ to be able to access my (internal) Domoticz instance from anywhere, securely over TLS. This appears to be working great. I've set up basic authentication (within Domoticz settings) with a long password to secure the access to the actual content.

As security is a large issue, my primary concern now is that a brute force attack on the password on my Domoticz instance is (1) not detected by me, and that (2) no preventive measures are taken to block/slow down the brute force attack.

So my first question is, can something like this (http://stackoverflow.com/questions/3539 ... rial-times) be implemented? Ideally with a 'block offending IP adress for x hours' feature, and preferably as an option to turn the option on or off, as some people don't need this.

The second question would be is it' possible to send a notification email when a brute force attack is detected?
Domoticz on Raspberry Pi2 with a RazBerry (V1.0), RFXcom USB, Greenwave (NUON) smart plug 6 & single smart plugs, Fibaro door/window sensors, Cresta temp sensors (433mhz), Z-wave.me wall controller/switch, Z-wave.me dimmer, KaKu ACM3500 etc
User avatar
gizmocuz
Posts: 2548
Joined: Thursday 11 July 2013 18:59
Target OS: Raspberry Pi / ODroid
Domoticz version: beta
Location: Top of the world
Contact:

Re: Basic authentication - maximum allowed attempts

Post by gizmocuz »

you can install fail2ban
Quality outlives Quantity!
garp
Posts: 7
Joined: Monday 30 September 2013 18:43
Target OS: Raspberry Pi / ODroid
Domoticz version:
Contact:

Re: Basic authentication - maximum allowed attempts

Post by garp »

I know, and i will. It would be great if that was not necessary, and domoticz could detect that and react by itself, instead of screwing around with fail2ban. Normal users will never get that working.
Domoticz on Raspberry Pi2 with a RazBerry (V1.0), RFXcom USB, Greenwave (NUON) smart plug 6 & single smart plugs, Fibaro door/window sensors, Cresta temp sensors (433mhz), Z-wave.me wall controller/switch, Z-wave.me dimmer, KaKu ACM3500 etc
Number8
Posts: 374
Joined: Friday 23 May 2014 7:55
Target OS: Linux
Domoticz version: 2022.1
Location: Saint Pierre de Jards
Contact:

Re: Basic authentication - maximum allowed attempts

Post by Number8 »

I have taken another route. I have an L2TP IPSec VPN setup on every devices that need to access Domoticz, including my phone. It proves to be an efficient solution.
Debian buster on NUC and three RPi with buster.
Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest