Brute force attack off user names in directory
-
I discovered that someone was brute forcing every single name with a single attempt per IP address of every user in the directory.
Seems like its a bad idea to show the actual log in names in the public directory.
I confirmed by changing a user name and the log in attempt name switched. Removing the directory and then changing them name resulted in them not knowing the new name.
Ah well. It was a nice comfy plugin until now. Switching to Profilegrid which has more privacy options.
Viewing 5 replies - 1 through 5 (of 5 total)
Viewing 5 replies - 1 through 5 (of 5 total)
- The topic ‘Brute force attack off user names in directory’ is closed to new replies.