Copied to clipboard

Flag this post as spam?

This post will be reported to the moderators as potential spam to be looked at


  • adrianfriend 67 posts 68 karma points
    Jan 12, 2012 @ 10:55
    adrianfriend
    0

    Password lockout for backend

    Hi Guys,

    Is the a number of password attempts on the Umbraco backend before lockout? I haven't been able to find out anywhere whether there is or not. If there isn't it would be theoretically possible for a hacker to attempt to crack the password of an account - if the hacker had knowledge of the site and it was using Umbraco it wouldn't take long to realise the username (admin).

    Also is there a way in the backend to change the password strength i.e. number of chars, special chars etc etc..

    Thanks,

    Adrian

    p.s. I suppose one way to get round it is to IP restrict the Umbraco backend?

  • adrianfriend 67 posts 68 karma points
    Jan 26, 2012 @ 15:46
    adrianfriend
    0

    Does anyone have an answer for the above?

    Our client is very keen to get an answer - I have tried adding :

    maxInvalidPasswordAttempts="5"

    passwordAttemptWindow="10" 

    minRequiredPasswordLength="8"

    They seem to be completly ignored!!

  • Adrian Chandler 3 posts 23 karma points
    Feb 17, 2012 @ 19:05
    Adrian Chandler
    0

    Yes, I'd like to know the answer to this too

  • This forum is in read-only mode while we transition to the new forum.

    You can continue this topic on the new forum by tapping the "Continue discussion" link below.

Please Sign in or register to post replies