Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Tambahkan anti brute-force di login #547

Closed
telo99 opened this issue Aug 12, 2017 · 3 comments
Closed

Tambahkan anti brute-force di login #547

telo99 opened this issue Aug 12, 2017 · 3 comments
Assignees
Labels
security Keamanan, perlu diperbaiki secepatnya.

Comments

@telo99
Copy link

telo99 commented Aug 12, 2017

Ada kemungkinan penyerang akan menggunakan metode brute force untuk mencoba masuk ke site manager.
Alangkah baiknya jika kesalahan login dibatasi hanya 10 misalnya (atau bisa juga dibuat agar pengguna bisa mengatur sendiri jumlahnya). Jika 10x gagal, blokir IP-nya selama 1 hari.

#SekedarIde #NggakTerlaluPenting :)

@eddieridwan eddieridwan added the security Keamanan, perlu diperbaiki secepatnya. label Aug 13, 2017
@eddieridwan eddieridwan changed the title Request: Anti bruteforce Tambahkan anti brute-force di login Aug 13, 2017
@eddieridwan
Copy link
Collaborator

Mungkin bisa diatasi dengan usul penambahan capcha di login, di issue #489.

@eddieridwan
Copy link
Collaborator

Setelah konsultasi dengan pengguna di https://www.facebook.com/groups/OpenSID/, pengguna lebih memilih cara menutup login sementara daripada menggunakan captcha.

@eddieridwan eddieridwan self-assigned this Nov 14, 2017
eddieridwan pushed a commit that referenced this issue Nov 14, 2017
… matikan form login siteman selama 5 menit setelah 3 kali gagal. [security-fix]
@eddieridwan
Copy link
Collaborator

Sudah dicommit ke master.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Keamanan, perlu diperbaiki secepatnya.
Projects
None yet
Development

No branches or pull requests

2 participants