Uploaded image for project: 'eZ Publish / Platform'
  1. eZ Publish / Platform
  2. EZP-20581

Limit subsequent login attempts to protect against brute force login attacks

    XMLWordPrintable

Details

    Description

      Brute force login can be stopped by limiting how many failed login attempts you're allowed to make. Rules should ideally be configurable, many options are possible:

      • Maximum X attempts per Y minutes
      • Lock account after X failures, optionally enable again after Y minutes
      • Lock account after X failures for Y minutes, after another X failures lock for Z minutes (larger value), can be increased further

      Limiting must be enforced server-side. Logging and admin notification would also be good.

      Attachments

        Activity

          People

            Unassigned Unassigned
            andre.romcke-obsolete@ez.no André Rømcke (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated: