Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7610163
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 31, 20262026-05-31T01:21:12+00:00 2026-05-31T01:21:12+00:00

Possible Duplicate: Preventing Brute Force Logins on Websites Limiting user login attempts in PHP

  • 0

Possible Duplicate:
Preventing Brute Force Logins on Websites
Limiting user login attempts in PHP

I wanted to know what would be a best way to prevent brute forcing in a log in form.
Meaning how can i save the number of tries and time limit? Would session be a good idea?

Thanks.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-31T01:21:13+00:00Added an answer on May 31, 2026 at 1:21 am

    You can automatically start a session for each person who hits your site. Then in the session variable, store the number of login attempts and if they are blocked, a time when they will be unlocked.

    When processing the login, if the password and username does not match and the time limit has not expired and the number of tries has been exceeded, display a message to the user.

    Your database table could look like this:

    sessions
    ==========
    id
    num_tries //Number of login attemps
    block_expires //If they are blocked, when they can be unblocked.
    

    This approach assumes that the user will assume a session cookie. They can easily get around this by clearing their cookies.

    In order to mitigate that some what, you can build some smarts into the process:

    • If the logins are coming from the same IP address AND the account they are trying to access does not change, then block the account (not the session!) for a set period of time.
    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Possible Duplicate: C# driver development? I would like to know if I can do
Possible Duplicate: PHP get all arguments as array? Within a javascript function arguments always
Possible Duplicate: php == vs === operator Reference - What does this symbol mean
Possible Duplicate: How to call a JavaScript function from PHP? I have a php
Possible Duplicate: How would I identify if a website originates from a mobile browser?
Possible Duplicate: How to: URL re-writing in PHP? How can a website use an
Possible Duplicate: How to minify php page html output? Any reason not to strip
Possible Duplicate: Best way to stop SQL Injection in PHP If I were to
Possible Duplicate: Symfony2 AJAX Login I have implemented a custom authentication handler service to
Possible Duplicate: Why not use tables for layout in HTML? Under what conditions should

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.