LibCrowds / libcrowds

The frontend for the LibCrowds crowdsourcing platform
MIT License
32 stars 6 forks source link

Penetration testing & security recommendations & #867

Open adikeinan opened 4 years ago

adikeinan commented 4 years ago

@harryjmoss noticed many failed attempts to log in to the Pybossa server and the dev and live frontend servers via ssh, with various accounts being tried and also attempts to log into the root account. Suggested using Fail2Ban to block IP addresses that fail to login multiple times.

Next step: NIIT to run security testing on the site and prioritise fixes.