Project

General

Profile

Actions

Feature #19987

closed

Security: Backend user should be disabled after x failed log in (and the appropriate option is set in the install tool)

Added by Vitali Stoller almost 16 years ago. Updated over 8 years ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
-
Start date:
2009-02-09
Due date:
% Done:

0%

Estimated time:
PHP Version:
5.2
Tags:
Complexity:
Sprint Focus:

Description

It's possible to attack the server and try to login as often as you want.
Backend user should be disabled after x failed log in.

This is also an Facebook etc. issue.

(issue imported from #M10388)


Related issues 2 (0 open2 closed)

Related to TYPO3 Core - Feature #75987: Implement request throttling/ rate limiting functionality and APIClosed2016-04-29

Actions
Is duplicate of TYPO3 Core - Bug #21658: Secure the BE login - Auto disable the be user after a certain amount of login failure.Closed2009-11-24

Actions
Actions #1

Updated by Steffen Müller almost 16 years ago

Careful with that. On the other hand this opens doors to DDOS attacks, when user accounts get disabled in masses - although they have proper passwords and don't fear any attack.

A better proposal would be "Backend user should be disabled after x failed log in and the appropriate option is set in the install tool."

Actions #2

Updated by Vitali Stoller almost 16 years ago

"A better proposal would be "Backend user should be disabled after x failed log in and the appropriate option is set in the install tool."

That would also have been my suggestion.

Actions #3

Updated by Alexander Opitz about 11 years ago

  • Tracker changed from Bug to Feature
  • Target version deleted (0)
Actions #4

Updated by Wouter Wolters almost 10 years ago

  • Status changed from New to Closed

Duplicate of #19987
Please continue there.

Actions #5

Updated by Thomas Sperling about 9 years ago

  • Status changed from Closed to New
  • Target version set to 6.2.16

Why is this Ticket closed and why isn't there any core-solution for several years?
If there are options in the InstallTool there is no reason to not have this really useful feature.

EDIT: there is a feature since 6.2.14: https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-006/ similiar but not exactly the wished feature

Actions #6

Updated by Riccardo De Contardi almost 9 years ago

  • Subject changed from Security: Backend user should be disabled after x failed log in to Security: Backend user should be disabled after x failed log in (and the appropriate option is set in the install tool)
  • Target version changed from 6.2.16 to Candidate for patchlevel
Actions #7

Updated by Helmut Hummel over 8 years ago

closed in favor of #75987

Actions #8

Updated by Helmut Hummel over 8 years ago

  • Status changed from New to Closed
Actions

Also available in: Atom PDF