On Wed, 29 Aug 2001, William Marcelo Piovezan wrote:

> Hi,
>
> The latest qmailadmin devel is not showing the error in Status Message (eg.
> "Invalid Domain" or "Invalid Password") when the user tries to login but
> make some mistake. When this occurs the login screen is showed again but
> the user do does not know what happened.
>
> Should not be better to create some dictionary entries (if they have not
> been created) and inform the user why the login could not to complete?

        Well, that could turn things easy for an intruder tring to guess
a passowrd/account name on you server.. Id he tries an account name and
the server returns "password invalid" he or she will knoe tha the account
exists, for example.

Daniel Lobato Duclos - [EMAIL PROTECTED] - http://www.cybershark.net
---------------------------------------------------------------------------
Open Up Your Mind / And Go Your Own Way
(Sepultura - Breed Apart)

Reply via email to