Re: User to get locked after three wrong login attempts.

Поиск
Список
Период
Сортировка
От Ron
Тема Re: User to get locked after three wrong login attempts.
Дата
Msg-id 1ea8bec3-1d0b-b69f-cbc0-c936860696f4@gmail.com
обсуждение исходный текст
Ответ на Re: User to get locked after three wrong login attempts.  (Craig James <cjames@emolecules.com>)
Список pgsql-admin
On 09/05/2018 05:14 PM, Craig James wrote:
[snip]
To elaborate, you should explain to the auditor that this introduces a huge denial-of-service vulnerability into your system. Anyone can start hammering on everyone else's accounts, and with a fairly trivial script, lock the entire company out of all accounts. This is a terrible idea.

And be tracked down (relatively) quickly.

--
Angular momentum makes the world go 'round.

В списке pgsql-admin по дате отправления:

Предыдущее
От: Craig James
Дата:
Сообщение: Re: User to get locked after three wrong login attempts.
Следующее
От: Tim Cross
Дата:
Сообщение: Re: User to get locked after three wrong login attempts.