Project

General

Profile

Actions

Bug #21658

closed

Secure the BE login - Auto disable the be user after a certain amount of login failure.

Added by Nikolas Hagelstein almost 15 years ago. Updated almost 10 years ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
-
Target version:
-
Start date:
2009-11-24
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
4.3
PHP Version:
4.3
Tags:
Complexity:
Is Regression:
No
Sprint Focus:

Description

Currently the TYPO3 backend login is not capable of any kind of brute force protection.

Suggestion:
Introduce an optional way to disable a certain backend user after a configurable amount of login failures.
Furthermore notifivy the admin whether a user has been locked out.

(issue imported from #M12720)


Related issues 3 (0 open3 closed)

Related to TYPO3 Core - Feature #21661: Secure the BE login - Blacklist ipsClosed2009-11-24

Actions
Related to TYPO3 Core - Feature #75987: Implement request throttling/ rate limiting functionality and APIClosed2016-04-29

Actions
Has duplicate TYPO3 Core - Feature #19987: Security: Backend user should be disabled after x failed log in (and the appropriate option is set in the install tool)Closed2009-02-09

Actions
Actions

Also available in: Atom PDF