Topic: Password reset flood

I think a flood limit on password reset requests would be handy in 1.3 (if it hasn't already been implemented).

I just had some kid thinking it's cool to refresh the page constantly, which resulted in one of my users being badly email bombed by my server.

I added in a limit so you can only reset once a day, I think it would help increase security even more in 1.3.

Sorry if its been suggested, couldn't find it using the search button though.

2 (edited by Mr Puto 2006-03-27 00:08)

Re: Password reset flood

I agree.

Re: Password reset flood

Yes, it has been mentioned before, but don't worry, I had quite a bit of trouble finding it via search also. A great as it is, search is not foolproof.

Anyway, some sort of protection sounds like a good idea to me, that is if it's not already planned (I vaguely remember reading a forum post saying so, but I just got through a major essay cramming session and I'm tired, so who knows, my brain could be playing tricks on me).

Looking for a certain modification for your forum? Please take a look here before posting.

Re: Password reset flood

pogenwurst wrote:

Yes, it has been mentioned before, but don't worry, I had quite a bit of trouble finding it via search also. A great as it is, search is not foolproof.

Anyway, some sort of protection sounds like a good idea to me, that is if it's not already planned (I vaguely remember reading a forum post saying so, but I just got through a major essay cramming session and I'm tired, so who knows, my brain could be playing tricks on me).

http://punbb.org/forums/viewtopic.php?pid=63773#p63773 big_smile
My search was easy compared to yours, I entered Rickard as the author and "1.3" (without the quotes) as the keywords tongue

Re: Password reset flood

Alright thanks, was just wanting to make sure 1.3 would have some kind of support for it, email flooding can be a big problem.