Hallo zusammen
Bin immer am überlegen wie ich Typo3 noch sicherer machen kann.
Weiss jemand wie man die Anzahl Login-Versuche auf die Seite
http://MeineSeite/typo3/
evtl auch:
http://www.MeineSeite/phpmyadmin/
etc.
begrenzen kann?
Z.B. mit Zeitverzögerungen bei falschen Passwort Eingaben.
Möchte so Passwort-Generatoren fernhalten.
Für einen Bescheid wäre ich sehr dankbar.
Viele Grüsse
Stäubel
Hallo,
über htaccess zb, bzw mal ins install-tool geschaut (unter all configuration)
> [warning_email_addr]: Email-address that will receive a warning if there has been failed logins 4 times within an hour (all users).
> [IPmaskList]: String. Lets you define a list of IP-numbers (with *-wildcards) that are the ONLY ones allowed access to ANY backend activity. On error an error header is sent and the script exits. Works like IP masking for users configurable through TSconfig. See syntax for that (or look up syntax for the function t3lib_div::cmpIP()
> [lockSSL]: If set (1+2+3), the backend can only be operated from an ssl-encrypted connection (https)
lg georg
just2b schrieb
> [warning_email_addr]: Email-address that will receive a warning if there has been failed logins 4 times within an hour (all users).
Hey cool, hatte ich gar nicht gesehen, dass man auch über Mail informiert werden kann.
Für alle die das auch machen möchten, einfach in der php.ini Datei noch ein Mail-Server eintragen.
z.B
[mail function]
; For Win32 only.
;SMTP = localhost
SMTP = 10.10.1.40 ;ist bei uns der interne Mailserver
smtp_port = 25
Gut wäre allerdings, wenn die Login-Seite gesperrt wird,
wenn zuviele falsche Passwörter eingegeben werden.
Solch eine Option hatte ich nicht gefunden #paralyzed#
just2b schrieb
> [IPmaskList]: String. Lets you define a list of IP-numbers (with *-wildcards) that are the ONLY ones allowed access to ANY backend activity. On error an error header is sent and the script exits. Works like IP masking for users configurable through TSconfig. See syntax for that (or look up syntax for the function t3lib_div::cmpIP()
Gut zu wissen, dass dies auch Typo3 kann,
das werde ich jedoch besser dem Firewall
vor dem Webserver beibringen.
just2b schrieb
> [lockSSL]: If set (1+2+3), the backend can only be operated from an
ssl-encrypted connection (https)
Das ist auch eine gute Idee, hatte jedoch damit mal den Typo3 versenkt 😃
Aber danke vielmals für die Tipps.
Grüsse Stäubel
N.B. Wäre es nicht vielleicht eine Idee einen Bereich für das Thema Sicherheit
in diesem Forum zu öffnen. Ich habe manchmal das Gefühl, die Sicherheit wird
manchmal ein wenig vernachlässigt.