DownloadTicketService / dl

Download Ticket Service
https://www.thregr.org/~wavexx/software/dl/
GNU General Public License v2.0
83 stars 30 forks source link

Brute-force countermeasures #46

Open wavexx opened 6 years ago

wavexx commented 6 years ago

We should allow to counteract to an hostile user trying to brute force either the ticket/grant ID space (by trying many invalid IDs) as well as invalid ticket/grant passwords.

wavexx commented 6 years ago

As an additional note, login/fetch attempts (succeeded or not) are now always logged. This actually plays rather nice with fail2ban.