42 dépôts
Mechanisms to limit failed authentication attempts and prevent unauthorized access.
Distinguishing note: Focuses on rate-limiting authentication specifically to prevent brute-force attacks.
Explore 42 awesome GitHub repositories matching security & cryptography · Brute Force Protections. Refine with filters or upvote what's useful.
This project provides a comprehensive collection of industry-standard guidelines for developing, testing, and deploying Node.js applications. It covers the entire software lifecycle, offering actionable advice on code style, architectural patterns, and security measures to ensure maintainability and consistency across large-scale codebases. The documentation details strategies for robust error management, containerization, and production readiness. It addresses operational requirements such as observability, scalability, and infrastructure configuration, while providing specific methodologies
Defines strategies for implementing rate limiting and account lockout mechanisms to mitigate unauthorized access attempts.
Payload is a headless content management system and application framework that uses a code-first approach to define data schemas and administrative interfaces. By utilizing a centralized, type-safe configuration object, it automatically generates database schemas, API endpoints, and a fully customizable admin panel. The system is built on a database-agnostic architecture, allowing it to interface with various storage engines while providing a unified, type-safe API for server-side operations, REST, and GraphQL. What distinguishes Payload is its deep extensibility and developer-centric design.
Limits failed login attempts to prevent brute-force attacks against authentication endpoints.
Devise is a comprehensive identity management system and authentication framework for Ruby on Rails applications. It provides a complete set of tools for managing user registration, secure sign-in, and session handling using a modular strategy pattern. The framework distinguishes itself by offering a suite of security hardening features, including brute force protection through account locking and secure password recovery workflows. It also functions as an integrator for external identity providers and third-party authentication via standardized protocols. Broad capabilities cover the full u
Protects accounts from brute force attacks by locking access after repeated failed login attempts.
DataEase is an open-source, self-hosted business intelligence platform designed for building interactive data visualizations and managing analytical reporting. It provides a centralized environment where users can construct dashboards through a drag-and-drop interface, connecting to diverse data sources including relational databases, data warehouses, and external APIs. The platform distinguishes itself through its focus on embedded analytics and enterprise-grade governance. It allows for the seamless integration of charts, dashboards, and management modules into third-party web applications
Protects accounts from brute-force attacks by limiting failed login attempts within specific timeframes.
Navidrome is a self-hosted music streaming server designed to organize, index, and stream personal digital music collections. It functions as a centralized audio streaming platform that manages local audio files, automatically enriching them with metadata and artwork while providing a web interface for playback. The system supports multi-user access, allowing administrators to manage separate collections and listening histories with granular permissions. The platform distinguishes itself through its compatibility with the Subsonic API, enabling users to connect a wide range of third-party mus
Implements security measures to throttle login attempts and block suspicious IP addresses, protecting user accounts from unauthorized access.
Wekan est un outil de gestion de projet Kanban open source et auto-hébergé utilisé pour organiser les flux de travail via des tableaux, des listes et des cartes. C'est une application web en temps réel qui permet aux équipes de gérer les tâches sur une infrastructure privée. La plateforme se distingue par des outils de migration de données étendus, spécifiquement pour l'importation de tableaux et de cartes depuis Trello. Elle prend en charge l'intégration d'identité de niveau entreprise via LDAP, OpenID Connect et OAuth2, et offre des options de stockage flexibles, notamment PostgreSQL comme backend relationnel principal et un stockage cloud enfichable pour les pièces jointes. Le système couvre un large éventail de capacités de gestion des tâches, y compris des visualisations de diagrammes de Gantt, le suivi du temps et l'agrégation des tâches entre les tableaux. Il inclut des outils administratifs pour le contrôle d'accès basé sur les rôles, la planification de sauvegardes automatisées et l'extensibilité programmatique via une API REST et des webhooks pilotés par les événements. L'application est disponible pour un déploiement via Docker et prend en charge les configurations multi-locataires.
Protects user accounts by locking them after repeated failed login attempts.
This project provides a full-stack, containerized mail server platform designed for self-hosting. It functions as a complete mail transfer agent that bundles essential services—including SMTP, IMAP, and POP3—into a unified environment. By leveraging container orchestration, it enables the deployment of private email infrastructure that handles message transport, delivery, and user management within a single, manageable service. The platform distinguishes itself through deep integration with container runtimes and robust configuration flexibility. It supports granular customization via configu
Protects against brute-force attacks by monitoring logs and blocking suspicious IP addresses.
Fail2ban is an intrusion prevention system that monitors system log files to detect malicious activity and automatically enforce security policies. By parsing log data in real time, the tool identifies patterns of unauthorized access or repeated authentication failures and responds by dynamically updating network access control lists to restrict offending sources. The software functions as a firewall automation tool that maintains stateful tracking of suspicious behavior across various network services. It utilizes a regex-driven pattern matching engine to identify specific attack signatures,
Automatically blocks IP addresses showing repeated failed login attempts to prevent brute force and credential stuffing.
Grav is a flat-file content management system that eliminates the need for a traditional database by storing site content and configuration in human-readable Markdown and YAML files. Built as a modular PHP web framework, it uses a hierarchical page routing system where the physical directory structure directly determines the site's URL paths. The platform is distinguished by its event-driven plugin architecture and a command-line interface that prioritizes system administration, deployment, and maintenance tasks. It utilizes a blueprint-driven system to generate administrative forms from stru
Provides built-in protection against brute-force attacks by limiting failed authentication attempts to secure the administrative interface.
Mail-in-a-Box is a self-hosted email server appliance that automates the deployment of SMTP, IMAP, and POP3 services on Linux. It functions as a complete suite including a DNS management server, a spam and abuse filter, and a web-based administrative control panel for managing users, aliases, and storage quotas. The project distinguishes itself through a high degree of automation for email security and authenticity. It automatically provisions and maintains SPF, DKIM, DMARC, and DNSSEC records to prevent domain spoofing, while managing the installation and rotation of TLS certificates and enf
Detects repeated failed login attempts and blocks offending IP addresses at the system firewall level.
SuperTokens Core is an open-source, self-hosted authentication and identity management platform designed for deployment within private infrastructure. It provides a comprehensive suite for managing user accounts, roles, and secure authentication flows, utilizing a modular, recipe-based architecture that allows developers to enable specific security features without modifying the core codebase. The platform distinguishes itself through its robust multi-tenancy capabilities, which allow for the logical or physical isolation of user records and configuration settings across different organizatio
Monitors sensitive action frequency to block brute-force attempts and prevent unauthorized account access.
Mealie is a self-hosted recipe management platform designed for personal data ownership and household meal planning. It functions as a digital kitchen assistant that allows users to import, organize, and digitize culinary content from websites, images, and videos into a structured, searchable database. The application supports multi-user collaboration through household management, enabling shared access to recipes and meal plans while maintaining distinct permissions. The platform distinguishes itself through extensive automation and integration capabilities. It features a programmatic interf
Enforces login attempt limits and account lockouts to protect against brute-force attacks.
This project is a web-based management interface designed for the administration, monitoring, and configuration of Nginx server instances. It functions as a centralized platform for managing reverse proxy settings, traffic routing, and server lifecycles, providing a visual dashboard to replace manual configuration file editing. The platform distinguishes itself through integrated infrastructure automation and observability tools. It supports distributed environments by synchronizing configuration states across multiple nodes and containerized services, while offering artificial intelligence a
Implements login attempt throttling to prevent brute-force attacks.
Lets-chat est une plateforme de communication d'équipe auto-hébergée et un serveur de chat XMPP conçu pour la messagerie privée. Il fournit un environnement de communication conteneurisé pour les petites équipes afin d'échanger des messages et des fichiers, avec une API REST programmable pour automatiser les conversations et gérer les messages depuis des outils externes. La plateforme fonctionne comme une passerelle et un serveur XMPP, assurant l'interopérabilité avec d'autres clients de messagerie conformes. Elle se distingue par la prise en charge de la gestion d'identité d'entreprise, permettant aux administrateurs de vérifier les identités des utilisateurs via des comptes locaux ou des services d'annuaire externes tels que LDAP et Kerberos. Le système couvre un large éventail de capacités de collaboration, incluant la messagerie directe privée, les salons de groupe protégés par mot de passe et la recherche dans l'historique des chats. Il gère la messagerie multimédia avec prise en charge des extraits de code, des mentions et de l'intégration de GIF tiers, tout en utilisant une couche de fournisseur pour router les téléchargements de fichiers vers des disques locaux ou du stockage cloud distant. L'application est packagée sous forme d'image conteneur pour un déploiement simplifié dans divers environnements et peut être configurée via des variables d'environnement.
Protects authentication endpoints by limiting failed login attempts to prevent brute-force attacks.
Kanboard est un outil de gestion de projet Kanban auto-hébergé et une suite de productivité conçue pour le suivi des tâches logicielles et la collaboration d'équipe. Il fournit un système visuel pour gérer les flux de travail via l'utilisation de tableaux, de colonnes et de cartes. Le projet dispose d'un framework de plugin extensible et d'une API complète pour l'administration programmatique des tâches et des projets. Il inclut une gestion d'identité spécialisée via l'intégration LDAP, permettant la synchronisation des comptes utilisateurs et des permissions de groupe depuis les serveurs d'annuaire. Le système couvre un large éventail de capacités, y compris l'automatisation du flux de travail pilotée par les événements, des analyses de projet détaillées telles que les graphiques d'avancement et la mesure du temps de cycle, et un contrôle d'accès granulaire basé sur les rôles. Il prend également en charge le suivi du temps intégré, la décomposition des sous-tâches et l'authentification multi-méthodes, y compris l'authentification à deux facteurs et le support de proxy inverse. L'application est compatible avec MySQL et PostgreSQL pour le stockage de données persistant et peut être déployée en utilisant Docker Compose.
Protects accounts against automated attacks by locking them and requiring CAPTCHAs after failed attempts.
all-in-one is a containerized deployment system designed to install and manage a complete suite of productivity and collaboration services. It functions as a cloud suite deployer that orchestrates the installation of a self-hosted content platform, incorporating necessary dependencies via Docker or Kubernetes. The project distinguishes itself by providing a web-based dashboard for orchestrating, updating, and monitoring the lifecycle of service containers. It also serves as a local AI inference server, enabling the execution of generative text models, image diffusion, and speech processing on
Integrates IP-level blocking to protect against brute-force authentication attacks.
Il s'agit d'une bibliothèque de hachage de mots de passe bcrypt et d'un module de cryptographie pour Node.js. Elle fournit un ensemble d'outils pour générer des sels sécurisés, calculer des hashs cryptographiquement forts et vérifier les mots de passe pour protéger les identifiants des utilisateurs contre les accès non autorisés. La bibliothèque implémente le hachage adaptatif, utilisant un facteur de coût configurable pour augmenter l'effort computationnel requis pour forcer les mots de passe par brute-force. Elle inclut un outil de vérification de mot de passe qui protège le processus de comparaison contre les attaques temporelles. Le projet couvre le hachage sécurisé des mots de passe et la génération de sels, ainsi que des utilitaires pour l'extraction du coût de hachage et la vérification des mots de passe. Ces capacités prennent en charge le stockage sécurisé des mots de passe et les flux de travail d'authentification des utilisateurs.
Employs salt and adaptive cost factors to significantly slow down password cracking attempts.
This project is a multimodal AI proxy and content generation hub that provides a unified web interface for interacting with multiple large language models and generative AI services. It functions as a secure API access gateway, routing requests from a single dashboard to various external AI backends using configurable base URLs and API keys. The platform is delivered as a cross-platform progressive web application, allowing for installation on Linux, Windows, and MacOS. It distinguishes itself by consolidating text, image, audio, and video generative controls into a standardized interface, su
Includes mechanisms to block repeated failed authentication attempts to prevent automated password guessing.
Roundcube is an open-source, self-hosted webmail client designed for reading, composing, and organizing emails stored on remote servers using IMAP and SMTP protocols. It provides a browser-based interface that allows users to manage their mailboxes and sender identities through a secure communication platform. The platform is distinguished by its modular architecture, featuring a plugin-based extension system for adding new functional modules and a skin-based theme layer for customizing the visual appearance and responsive layouts. It further supports embedding its interface into external clo
Protects user accounts using brute-force prevention, two-factor authentication, and external identity provider support.
CTFs as you need them
Limits challenge attempts and hides challenges to automatically protect against brute force attacks.