Item9295: Configure does not log failed password attempts

Priority: Normal
Current State: Closed
Released In: 1.1.0
Target Release: minor
Applies To: Engine
Component: configure
Reported By: GeorgeClark
Waiting For:
Last Change By: KennethLavrsen
Configure doesn't log failed password attempts. This allows unlimited and undetected attacks against configure without any record.

This shouldn't be happening if configure is locked down as recommended, restricted to IP and http authentication. But attempts should still be logged.

-- GeorgeClark - 10 Jul 2010


ItemTemplate edit

Summary Configure does not log failed password attempts
ReportedBy GeorgeClark
SVN Range
AppliesTo Engine
Component configure
Priority Normal
CurrentState Closed
Checkins distro:67e249235f0e distro:28831d974512
TargetRelease minor
ReleasedIn 1.1.0
Topic revision: r5 - 04 Oct 2010, KennethLavrsen - This page was cached on 01 Dec 2015 - 12:55. Get a fresh version here.
The copyright of the content on this website is held by the contributing authors, except where stated elsewhere. See Copyright Statement. Creative Commons License