NetCommunity and Failed Password Attempts

Options
Is there any kind of failed password lockout feature on NetCommunity? It seems like I can just keep guessing passwords and with a bit of luck/time, an attacker could have access to my whole website. A brute force attack would probably be quite successful here which I see as a major security problem.


I'd like to be able to lock an account, particularly an admin account, after say 5 failed login attempts.


Anyone got any thoughts or workarounds to this?
Tagged:

Comments

  • Hi Gerald,


    We can toggle these settings within Blackbaud NetCommunity. When logged in with a supervisor account, navigate to Administration > Sites & settings. After clicking on the site on the left, scroll down to to the Registration and login options section. Here we can configure the allowed maximum number of failed login attempts as well as the account lockout duration:

    b9ee81f6690a8e3a4dfbbd115e71a703-huge-lo


    Once the maximum number of attempts has been reached, the account will be locked for the established period. If we edit the user in Users & security > Users, we'll see that the account is locked and can manually unlock the account if necessary:

    a1608a49f90640c29bc9314a5d33eafb-huge-lo

     

Categories