Advanced search  

News:

CPG Release 1.6.26
Correct PHP8.2 issues with user and language managers.
Additional fixes for PHP 8.2
Correct PHP8 error with SMF 2.0 bridge.
Correct IPTC supplimental category parsing.
Download and info HERE

Pages: [1]   Go Down

Author Topic: brute force login  (Read 7466 times)

0 Members and 1 Guest are viewing this topic.

cpinetree

  • Coppermine newbie
  • Offline Offline
  • Posts: 7
brute force login
« on: July 20, 2008, 11:43:32 pm »

using coppermine V1.4.18 it seems that after trying to login 3 times (what my setting is set for) that the only time the screen showing you are blocked from this site comes up, is after supplying the correct username + password.
In a nutshell you can continue to brute force the login screen until seeing the permission denied screen, you then know a correct user + password, wait until the block time has expired, and login normally.
Is there a way to show the denied screen after 3 failed login attempts, and ban until the time is up??
Logged

Nibbler

  • Guest
Re: brute force login
« Reply #1 on: July 21, 2008, 10:23:55 am »

Please post a link to your gallery and an account to test with.
Logged

cpinetree

  • Coppermine newbie
  • Offline Offline
  • Posts: 7
Re: brute force login
« Reply #2 on: July 21, 2008, 10:43:50 pm »

I sent an email to you with the info, as I prefer not to post it publicly.
thanks for your help.
Logged

cpinetree

  • Coppermine newbie
  • Offline Offline
  • Posts: 7
Re: brute force login
« Reply #3 on: August 01, 2008, 01:15:38 am »

Just wondering if there is any news on this?

can anyone else duplicate this on their installs?

I thought it might get moved to the bug board if other people have the same issue.
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: brute force login
« Reply #4 on: August 01, 2008, 07:47:54 am »

It certainly won't get moved to the bugs board, as yours is not a valid bug report. The fact that others have the same issue doesn't make it a bug, but just a lot of pilot errors that can come from many different sources (client apps interfering, users forgetting their passwords, fantastico installs acting up, invalid cookie names, broken cookies in the browser, the browser not being configured properly yadda yadda). With an app being so popular, it's understandable that there are some users asking for support on a lot of things. This doesn't mean that features are buggy, but just that this is a busy forum and Coppermine a popular app.
Do as Nibbler suggested: he didn't ask to be sent a message - he asked you to post publicly. Not doing as suggested usually results in getting ignored.
Logged

Nibbler

  • Guest
Re: brute force login
« Reply #5 on: August 01, 2008, 10:23:40 am »

Works as expected for me.
Logged

cpinetree

  • Coppermine newbie
  • Offline Offline
  • Posts: 7
Re: brute force login
« Reply #6 on: August 01, 2008, 10:03:17 pm »

Thank's for looking into this nibbler.
I think the application is great, and I have added additional logging so I will know if someone is trying to brute force the login.

Joachim Müller, I was not Ignored as you suggest, nibbler had made some tests, I was trying to get input from others to see if it might be a problem with my browser, server, etc.
Your reply to this problem was both unnecessary and very condescending, as you gave no actual feedback about the problem, only possibilities that it may be due to my misconfiguration etc. I would welcome your feedback on how this works in your installation. I do not see an install on your web page or would have tried a few logins to see my results.

again,
   Thanks to all the developers and the helpful people in this community for a great program!
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: brute force login
« Reply #7 on: August 01, 2008, 11:04:52 pm »

You proposed moving this thread to the bigs board and I told you that it won't get moved and also told you why. My testbed is none of your business, but I have more than one page that I maintain. If you want to perform tests, do so on the demo we provide.
Logged
Pages: [1]   Go Up
 

Page created in 0.023 seconds with 19 queries.