Skip to content

No restriction on password attempts allows for brute-force attacks #1138

@vityuasd

Description

@vityuasd

Data

  • Shiori version: 1.7.4 and earlier
  • Database Engine: SQLite
  • Operating system:windows docker

Describe the bug / actual behavior

No restriction on password attempts allows for brute-force attacks.

Expected behavior

Brute-force until successful login.

To Reproduce

  1. Navigate to the login page.
  2. Capture the login POST request with Burp Suite.
  3. Use the Intruder tool to perform the brute-force attack.

Screenshots

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    type:bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status
    To do

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions