# Question on brute force detection

**URL:** <https://help.nextcloud.com/t/question-on-brute-force-detection/7488>\
**Category:** 🗃️ Hosting providers\
**Created:** [January 13, 2017, 8:04am UTC](https://help.nextcloud.com/t/question-on-brute-force-detection/7488 "2017-01-13T08:04:38Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Holger\_Beetz](https://help.nextcloud.com/letter_avatar/holger_beetz/32/5_5575768a8748004e209b776fc1b2916d.png) [@Holger\_Beetz](https://help.nextcloud.com/u/Holger_Beetz)\
**Post date:** [January 13, 2017, 8:04am UTC](https://help.nextcloud.com/t/question-on-brute-force-detection/7488/1 "2017-01-13T08:04:38Z")

</div>

Hi there,

we are currently experimenting with Nextcloud for exchanging files with external users and customers.  
Yesterday someone used the Nextcloud mobile device client with wrong credentials. This caused the brute force detection to kick in and making log ins from our internal subnet very slow.

Some questions in regard to this since the manual didn’t provide much informations on this or may be I missed it.

1. Are all logins from a specific subnet / IP slowed down if brute force detection has kicked in ?

2. Is the database table cleaned up after some time by a cron job ? I mean like everyday midnight ?

If #1 is true this could cause serious trouble for us if some internal user enters a wrong PW multiple times and this causes slow logins for any other inhouse user when accessing our Nextcloud server.

Hopefully someone can shed a bit of light in my darkness 🙂

TIA,  
Holger

---

<div class="post-metadata">

**Author:** ![Soko](https://help.nextcloud.com/user_avatar/help.nextcloud.com/soko/32/100_2.png) [@Soko](https://help.nextcloud.com/u/Soko)\
**Post date:** [January 13, 2017, 8:28am UTC](https://help.nextcloud.com/t/question-on-brute-force-detection/7488/2 "2017-01-13T08:28:38Z")

</div>

[quote=“Holger\_Beetz, post:1, topic:7488”]  
Are all logins from a specific subnet / IP slowed down if brute force detection has kicked in ?[/quote]

Yes, they are.

> Is the database table cleaned up after some time by a cron job ? I mean like everyday midnight ?  
> Yes

You can disable it:

> <https://github.com/nextcloud/server/blob/c76dc835c4a1abc179bef3c469d837946fe4d339/config/config.sample.php#L210-L215>

---

<div class="post-metadata">

**Author:** ![Holger\_Beetz](https://help.nextcloud.com/letter_avatar/holger_beetz/32/5_5575768a8748004e209b776fc1b2916d.png) [@Holger\_Beetz](https://help.nextcloud.com/u/Holger_Beetz)\
**Post date:** [January 13, 2017, 8:32am UTC](https://help.nextcloud.com/t/question-on-brute-force-detection/7488/3 "2017-01-13T08:32:53Z")

</div>

Thanks for your reply ! So one stupid / unaware user can cause big troubles here ☹

What about an included cleanup job ? Is something like this available or do I need write a small sql script cleaning up the table ?

Thanks for pointing out that I can disable this but I would rather leave this in place with some automatism behind cleaning up all entries from our internal subnet at a choosen interval.

---

<div class="post-metadata">

**Author:** ![Soko](https://help.nextcloud.com/user_avatar/help.nextcloud.com/soko/32/100_2.png) [@Soko](https://help.nextcloud.com/u/Soko)\
**Post date:** [January 13, 2017, 8:38am UTC](https://help.nextcloud.com/t/question-on-brute-force-detection/7488/4 "2017-01-13T08:38:03Z")

</div>

Sorry, I was shure, they are cleaned from the database. But now I hat a look into my database and saw, that I have Data in oc\_bruteforce\_attempts table since August 2016.

I have a further look and will come back to that thread…

> So one stupid / unaware user can cause big troubles here

Yes…

---

<div class="post-metadata">

**Author:** ![Soko](https://help.nextcloud.com/user_avatar/help.nextcloud.com/soko/32/100_2.png) [@Soko](https://help.nextcloud.com/u/Soko)\
**Post date:** [January 13, 2017, 8:48am UTC](https://help.nextcloud.com/t/question-on-brute-force-detection/7488/6 "2017-01-13T08:48:46Z")

</div>

If now deleted the last test-bruteforce attempts manualy from oc\_bruteforce\_attempts table and the bruteforcedelay didn’t ocure anymore…

---

<div class="post-metadata">

**Author:** ![Holger\_Beetz](https://help.nextcloud.com/letter_avatar/holger_beetz/32/5_5575768a8748004e209b776fc1b2916d.png) [@Holger\_Beetz](https://help.nextcloud.com/u/Holger_Beetz)\
**Post date:** [January 13, 2017, 8:49am UTC](https://help.nextcloud.com/t/question-on-brute-force-detection/7488/7 "2017-01-13T08:49:32Z")

</div>

It would be very nice if you can give me feedback on the cleanup.  
BTW: The disable flag for bruteforce detection in the config.php seems to be ignored if there are any entries in the oc\_bruteforce\_atempts table. Only if the table is empty the flag seems to be valued by Nextcloud.

---

<div class="post-metadata">

**Author:** ![Holger\_Beetz](https://help.nextcloud.com/letter_avatar/holger_beetz/32/5_5575768a8748004e209b776fc1b2916d.png) [@Holger\_Beetz](https://help.nextcloud.com/u/Holger_Beetz)\
**Post date:** [January 13, 2017, 8:53am UTC](https://help.nextcloud.com/t/question-on-brute-force-detection/7488/8 "2017-01-13T08:53:45Z")

</div>

This is similar to what we did yesterday by truncating the table 🙂

But in the end there seems to be no automatism but any user from a certain subnet gets slowed down for ever once he is on the blacklist. I am not shure if this is a great idea. Especially if you run into this issue for the first time. We had first other issues in mind when the login took so long. Like slow database or problems with the webserver.

I guess both a flag about a kicked in brute force detection in the webfront end plus some option to clean the table automatically would be a nice enhancement.

Thanks again for taking the time to answer.

---

<div class="post-metadata">

**Author:** ![Soko](https://help.nextcloud.com/user_avatar/help.nextcloud.com/soko/32/100_2.png) [@Soko](https://help.nextcloud.com/u/Soko)\
**Post date:** [January 13, 2017, 9:04am UTC](https://help.nextcloud.com/t/question-on-brute-force-detection/7488/9 "2017-01-13T09:04:56Z")

</div>

Sorry, I remebered wrong about the cleaning ☹

But have a look at this pr:

> <https://github.com/nextcloud/server/pull/2095>

---

<div class="post-metadata">

**Author:** ![Holger\_Beetz](https://help.nextcloud.com/letter_avatar/holger_beetz/32/5_5575768a8748004e209b776fc1b2916d.png) [@Holger\_Beetz](https://help.nextcloud.com/u/Holger_Beetz)\
**Post date:** [January 13, 2017, 9:51am UTC](https://help.nextcloud.com/t/question-on-brute-force-detection/7488/10 "2017-01-13T09:51:22Z")

</div>

Ah cool…this would help. I will have a look at this feature.

---

<div class="post-metadata">

**Author:** ![guddl](https://help.nextcloud.com/user_avatar/help.nextcloud.com/guddl/32/956_2.png) [@guddl](https://help.nextcloud.com/u/guddl)\
**Post date:** [January 13, 2017, 5:08pm UTC](https://help.nextcloud.com/t/question-on-brute-force-detection/7488/11 "2017-01-13T17:08:20Z")

</div>

An other feature request:

> <https://github.com/nextcloud/server/issues/3058>
