[go: nahoru, domu]

Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is there any chance to add an anti-BFA mechanism? #13111

Closed
ghost opened this issue Mar 21, 2017 · 3 comments
Closed

Is there any chance to add an anti-BFA mechanism? #13111

ghost opened this issue Mar 21, 2017 · 3 comments
Assignees
Labels
question Used when we need feedback from the submitter or when the issue is a question about PMA

Comments

@ghost
Copy link
ghost commented Mar 21, 2017

I am not a PHP programmer or a security expert. Yet I humbly ask if it is possible to add an anti Brute Force Attack (BFA) mechanism?

AFAIK, the current situation is that users must manually create one themselves via Fail2Ban or LFD. This task requires considerable knowledge in Linux, Regular expressions, and and programming, and doesn't suit to the average user.

I hope you would consider adding such a mechanism. Ben,

@nijel
Copy link
Contributor
nijel commented Mar 21, 2017

Yes, you can enable captcha on login page. Generally I can recommend reading Securing your phpMyAdmin installation in our documentation.

@nijel nijel closed this as completed Mar 21, 2017
@nijel nijel self-assigned this Mar 21, 2017
@nijel nijel added the question Used when we need feedback from the submitter or when the issue is a question about PMA label Mar 21, 2017
@ghost
Copy link
Author
ghost commented Mar 21, 2017

What about BFA preventor like "5 Tries already, try again in 30 minutes" (or any time setted by the user) ?

@nijel
Copy link
Contributor
nijel commented Mar 21, 2017

There is nothing we could do out of the box as some persistent storage is needed to make it effective, see discussion in #4349.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Jun 2, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
question Used when we need feedback from the submitter or when the issue is a question about PMA
Projects
None yet
Development

No branches or pull requests

1 participant