5 Jul 2010, 9:30 PM

i want to set the cookie before the login like:if the user fails to login by typing wrong user id or password 5 times in 15 minutes then he should be restricted for the next 15 minutes to login.. should recieve an alert or message on window(just like gmail or yahoo)

5 Jul 2010, 11:05 PM
2) I would save wrong authentications in a database (with timestamp and counter)
-> if you save it in a cookie, it's simple for the user (or a cracker) to delete the cookie
-> you could have a table called "authenticationFailed" or something where are 4 columns:
id | userid | counter | time | ip

id is an endless number.
userid is the id of the user which tried to log in
counter is the number of wrong log-ins
time is a timestamp of the last wrong login
ip is the ip adress of the last user who tried to log in

you have to set the counter to 0 if the authentication was succesfully.

I bet you would have had the same idea if you think about what your problem is... This is nothing special, no magic and maybe not the best solution but.. it works.. ;)