glFusion / glfusion

glFusion CMS - Advanced Content Management with Style
https://www.glfusion.org
GNU General Public License v2.0
14 stars 15 forks source link

User throttling can lead to a DOS #583

Open leegarner opened 2 years ago

leegarner commented 2 years ago

With the new user auth mechanisms, I'm finding that bots can cause a DOS on a root or admin account. Something that should be looked into, maybe banning addresses after repeated attempts instead of just throttling the account.