[web2py] Re: cibersecurity audit issue about login

2023-12-31 Thread Dave S
On Thursday, November 16, 2023 at 9:32:58 AM UTC-8 Ramos wrote: Hello friends, i guess this is a similar issue between web2py and py4web so im posting to both groups. Sorry if im abusing ... We had a cibersecurity audit in our web2py app and they found this issue QUOTE During the application

[web2py] Re: cibersecurity audit issue about login

2023-11-16 Thread Christian Varas
Hello António. Bruteforce in login is a common weakness that can be easy to solve. The most effective solution is implementing a CAPTCHA, in web2py I use google recaptcha because the implementation is easy and stops all the automations. In py4web I'm still unable to implement it in the login form