- Aug 31, 2011
-
-
rswindell authored
-
rswindell authored
-
rswindell authored
-
rswindell authored
from the same host (but not necessarily the same connection). No login retry is allowed for suspected hackers (one authentication attempt per connection). New-connections from suspected hack hosts are now delayed increasingly with the number of failed login attempts.
-
rswindell authored
from the same host (but not necessarily the same connection). No login retry is allowed for suspected hackers (one authentication attempt per connection). Other FTP hack.log entries contain a little more detail about the type of suspected hack attempt (e.g. "FTP BOUNCE").
-
rswindell authored
-
rswindell authored
file attachments in netmail. Added [N]etmail command to Renegade clone email menu.
-
- Aug 30, 2011
-
-
rswindell authored
JSexec confirm function now prompts user and return value is based on their response.
-
rswindell authored
-
rswindell authored
especially through SMTP (where these values are exposed via the Originator-info header field): SENDERUSERID, SENDERSERVER, and SERVERTIME.
-
rswindell authored
especially through SMTP (where these values are exposed via the Originator-info header field): SENDERUSERID, SENDERSERVER, and SERVERTIME.
-
rswindell authored
as well as disallow semicolons in user-names.
-
- Aug 27, 2011
-
-
rswindell authored
Added the "Originator-info" header field for transmitted messages which will help track the original submission, especially when submitted via protocols other than SMTP. The RECIPIENT/To header field for SMTP-submitted msgs now contains the parsed "To:" name, if possible (instead of the address). Added security delay to failed SMTP AUTH-MD5 logins.
-
rswindell authored
telnet_gate() now enables the telnet command pass-through after negotiating necessary options. This doesn't quite fix the problem reported with telgating to nethack.alt.org, but it's a step in the right direction.
-
deuce authored
-
- Aug 26, 2011
- Aug 25, 2011
-
-
mcmlxxix authored
-
mcmlxxix authored
-
mcmlxxix authored
-
deuce authored
-
rswindell authored
not known.
-
rswindell authored
-
rswindell authored
-
rswindell authored
(based on text/password.can).
-
mcmlxxix authored
-
rswindell authored
-
rswindell authored
-
rswindell authored
-
rswindell authored
programs) and a nice message to the user explaining that they can't use any such password.
-
rswindell authored
optional rejection message file (text/badpassword.msg) - this file is where the sysop should add common/obvious passwords like "password".
-
rswindell authored
- added 5 second delay before responding to POP or SMTP client regarding invalid username or password attempt (limit number of effective brute force hack attempts per minute). - increment the user email sent statistics for authenticated SMTP msg recvs - check the configured max emails per day value (for the user's security level) and reject any messages that would exceed this value (exept for 'M'-exempt users) - this has been on the todo list for a long time.
-
rswindell authored
unlimited number of emails per day.
-
- Aug 24, 2011
- Aug 22, 2011
- Aug 16, 2011