W

Failed login returns 200 status code

  • Thread starter Thread starter W1zzard
  • Start date Start date

Visitor Greeting

Welcome to NullWarehouse.com... We are currently seeking Mod's and Contributors. If you wish to apply for a Mod position then please click on Members dropdown arrow, then click on Staff App and fill it out completely and submit it. If you want to be a Contributor then start contributing and we will have our eye on you and take notice, something great could come of it.

  • We have redone the forum. If you notice any issues or errors please open a Support Ticket under the Members dropdown and let us know.
W

W1zzard

Guest

This makes it hard to catch bruteforces in the logs, should return 401

edit:
SELECT COUNT(*) FROM xf_login_attempt WHERE FROM_UNIXTIME(attempt_date) > CURRENT_DATE()
-> 184468

and it's only 5 pm

fix:
edit LoginController.php, after $user = $loginService->validate($input['password'], $error);

change
return $this->view('XF:Login\Form', 'login', $viewParams);

to

$view = $this->view('XF:Login\Form', 'login', $viewParams)...

Read more

Continue reading...
 
Back
Top Bottom