Skip to content
Snippets Groups Projects
Commit 30f91280 authored by Jared Hancock's avatar Jared Hancock
Browse files

oops: Don't log or email the clear text user+pass

parent 30a3d2c0
No related branches found
No related tags found
No related merge requests found
...@@ -872,13 +872,13 @@ class UserAuthStrikeBackend extends AuthStrikeBackend { ...@@ -872,13 +872,13 @@ class UserAuthStrikeBackend extends AuthStrikeBackend {
if($authsession['strikes']>$cfg->getClientMaxLogins()) { if($authsession['strikes']>$cfg->getClientMaxLogins()) {
$authsession['laststrike'] = time(); $authsession['laststrike'] = time();
$alert='Excessive login attempts by a user.'."\n". $alert='Excessive login attempts by a user.'."\n".
'Login: '.$username.': '.$password."\n". 'Username: '.$username."\n".
'IP: '.$_SERVER['REMOTE_ADDR']."\n".'Time:'.date('M j, Y, g:i a T')."\n\n". 'IP: '.$_SERVER['REMOTE_ADDR']."\n".'Time:'.date('M j, Y, g:i a T')."\n\n".
'Attempts #'.$authsession['strikes']; 'Attempts #'.$authsession['strikes'];
$ost->logError('Excessive login attempts (user)', $alert, ($cfg->alertONLoginError())); $ost->logError('Excessive login attempts (user)', $alert, ($cfg->alertONLoginError()));
return new AccessDenied('Access Denied'); return new AccessDenied('Access Denied');
} elseif($authsession['strikes']%3==0) { //Log every other third failed login attempt as a warning. } elseif($authsession['strikes']%3==0) { //Log every third failed login attempt as a warning.
$alert='Login: '.$username.': '.$password."\n".'IP: '.$_SERVER['REMOTE_ADDR']. $alert='Username: '.$username."\n".'IP: '.$_SERVER['REMOTE_ADDR'].
"\n".'TIME: '.date('M j, Y, g:i a T')."\n\n".'Attempts #'.$authsession['strikes']; "\n".'TIME: '.date('M j, Y, g:i a T')."\n\n".'Attempts #'.$authsession['strikes'];
$ost->logWarning('Failed login attempt (user)', $alert); $ost->logWarning('Failed login attempt (user)', $alert);
} }
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment