[wp-trac] [WordPress Trac] #24193: Anti brute force protection

WordPress Trac noreply at wordpress.org
Thu Apr 25 20:32:20 UTC 2013


#24193: Anti brute force protection
-------------------------+------------------------------
 Reporter:  MAzZY        |       Owner:
     Type:  enhancement  |      Status:  new
 Priority:  normal       |   Milestone:  Awaiting Review
Component:  Users        |     Version:  3.5.1
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+------------------------------

Comment (by mpol):

 I'm sure some ideas are possible, not all ideas are bad or unworkable. I
 like the Captcha idea after 3 failed login attempts.
 Another idea is to wait 3 seconds if the password is wrong. Just like SSH
 does. I'll attach a patch for that (very simple).
 I'm sure other ideas are welcome here. There's not a single solution, but
 some ideas will make it for the attackers less convenient.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/24193#comment:3>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list