Page 1 of 1

Login Page gives too much information

Posted: Wed Nov 24, 2021 5:49 pm
by Haweh
When attempting to login to the game, the login form will tell you specifically if your username or password is wrong. It should be changed to be more vague. An attacker could attempt to find valid usernames by trying different usernames until "Invalid Password" error appears instead of "Invalid username."

Suggestion:
Change the error message to be a generic "Username or password is incorrect." or "Invalid credentials entered.", etc.

Re: Login Page gives too much information

Posted: Wed Nov 24, 2021 7:10 pm
by Badziew
I think that part is just stock PHPBB code with no possibility to customize, although maybe there is a PHPBB plugin somewhere that hacks into that part. But in terms of security the less plugins the better, so...

Re: Login Page gives too much information

Posted: Thu Nov 25, 2021 7:42 pm
by plscks
I don't think this one should be that hard to change to something less specific. Testing a fix seems to work on dev server so far.

Re: Login Page gives too much information

Posted: Sat Feb 26, 2022 12:18 pm
by SaltedSalmon
plscks wrote: Thu Nov 25, 2021 7:42 pm I don't think this one should be that hard to change to something less specific. Testing a fix seems to work on dev server so far.
Has this been implemented? It has been a while.

Re: Login Page gives too much information

Posted: Sat Feb 26, 2022 12:42 pm
by Goliath
Has this been implemented? It has been a while.
I tested this with my username and wrong password, and with a random username and something as password.
It hasn't been implemented.
Image
Image

Re: Login Page gives too much information

Posted: Sun Feb 27, 2022 3:24 pm
by plscks
Goliath wrote: Sat Feb 26, 2022 12:42 pm
Has this been implemented? It has been a while.
I tested this with my username and wrong password, and with a random username and something as password.
It hasn't been implemented.
Image
Image
I believe this was updated in the latest game update. Thank you for the reminder!

Re: Login Page gives too much information

Posted: Sun Feb 27, 2022 3:47 pm
by Goliath
Seems to be working now, lovely