Project

General

Profile

Actions

Feature #16485

closed

Security enhancement

Added by Torkil Svensgaard over 17 years ago. Updated over 12 years ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
felogin
Target version:
-
Start date:
2006-08-23
Due date:
% Done:

0%

Estimated time:
PHP Version:
Tags:
Complexity:
Sprint Focus:

Description

As it is now, I could enter a random (valid) email address and an email would go out to the owner, telling him the email isn't known by the system.

If I thought that was funny, I could do it again. At some point, this might get the mail server blacklisted.

If I happened to use an email address know by the system, the same thing would happen, just a different type of email being sent.

How about some configuration options, giving the site owner the ability to allow/ disallow the sending of emails in the case where the email is unknown to the system and introduce some simple measure (Pets name!) to avoid randoms to spam an email address known by the system?

(issue imported from #M4088)


Files

newloginbox_pi1.tar.bz2 (18 KB) newloginbox_pi1.tar.bz2 Administrator Admin, 2007-11-14 13:19

Related issues 1 (0 open1 closed)

Related to TYPO3 Core - Bug #17751: Lost password and not email active in database, why send a mail ?ClosedSteffen Kamper2007-11-03

Actions
Actions

Also available in: Atom PDF