Giter VIP home page Giter VIP logo

Comments (3)

danpros avatar danpros commented on June 22, 2024

Hello,

To modify the /login and /admin path, it needs quite a lot of changes.

htmly using bcrypt as the hash algo (default as of PHP 5.5.0). With good password, at least 8 char and contains upper, lower, number and symbols it need 286 years to crack it (info).

To prevent brute force, you can enable the Google reCaptcha (link).

Good luck! 😃

from htmly.

oleteacher avatar oleteacher commented on June 22, 2024

Thank you for the input Dan.

The issue is not the security of the script. Issue is: one school campus that has 10+ teachers with internet facing blog to keep parents updated. This is just one campus. Multiply that by 20+ campuses. 200+ installs of HTMLY with all of them using admin/ and/or login/. The amount of rouge traffic is staggering, hits that just keep coming hour after hour 24/7.

The IT department will just not allow such.

Anyway, thank for reply.

from htmly.

vdbhb59 avatar vdbhb59 commented on June 22, 2024

Thank you for the input Dan.

The issue is not the security of the script. Issue is: one school campus that has 10+ teachers with internet facing blog to keep parents updated. This is just one campus. Multiply that by 20+ campuses. 200+ installs of HTMLY with all of them using admin/ and/or login/. The amount of rouge traffic is staggering, hits that just keep coming hour after hour 24/7.

The IT department will just not allow such.

Anyway, thank for reply.

Teachers can keep logged in or use another IP for login and then switch to campus wifi. However, that is a temporary solution, up until your issue is resolved. Another way is to add each one as a user to one installation itself. Grant them admin rights and that should minimize hopefully.

from htmly.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.