Menu

#269 Login error (2)

Reproducible
closed-fixed
5
2004-10-15
2004-10-14
No

Another probably related login error:

If I try to login with username X and false password,
NOCC still seems to load the user X's name and address
from preferences file, and even show this information in
the "too many login failures" page, and also in the login
screen after browsers Back button.

I consider this a security flaw. No information from user
X should be retrieved, never mention displayed in the
screen, if password is incorrect.

Discussion

  • Anonymous

    Anonymous - 2004-10-15

    Logged In: YES
    user_id=529507

    Fixed in CVS.

    It'll be included in next release.

    But you can download daily snapshots at :
    http://nocc.sourceforge.net/download/

    Thanks for the bug report.

     
  • Anonymous

    Anonymous - 2004-10-15
    • assigned_to: nobody --> goddess_skuld
    • status: open --> closed-fixed
     

Log in to post a comment.

MongoDB Logo MongoDB