Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[F] CAPTCHA login protection bug [R] [C-Rcpalace]
#21
(12-04-2008, 07:49 PM)TStarGermany Wrote:  i tested a bit more
i set the "Number of times to allow failed logins" to "0" in the board config ...

// If it somehow works on your host, then good for you.

I was hoping your suggestion might work around the bug, while still protecting the board.
When I set failed logins" to "0", then the protection was disabled, just like it is supposed to be.

Later, setting it to '4', followed by more incorrect logins, produced the screen with the Captcha (this time)
#
MyBB is the best forum software! Exclamation

#22
*headscratch*
that stuff doesn't make sense Sad
[Image: 350x19.jpg][Image: tstargermany.png]
#23
Ok so we've got symptoms all over the place and multiple bug report in one thread. Before I get completely lost, can someone provide some concise and clear reproduction instructions. And if there are other bugs, then it would be best to create a new thread for each one.
#24
Ok, so how many of you have the Login Convert (with the Merge System) plugin enabled?
#25
@ryan: i don't even know what that is, so i guess no Smile
[Image: 350x19.jpg][Image: tstargermany.png]
#26
(12-04-2008, 09:48 PM)Ryan Gordon Wrote:  Ok, so how many of you have the Login Convert (with the Merge System) plugin enabled?

No

(12-04-2008, 07:18 PM)TStarGermany Wrote:  ... i fail to see any information about failedlogins....

MyBB (Firefox) cookies contain a cookie for failed login attempts, I just saw it myself.

(12-04-2008, 09:37 PM)Ryan Gordon Wrote:  Ok so we've got symptoms all over the place and multiple bug report in one thread. Before I get completely lost, can someone provide some concise and clear reproduction instructions. And if there are other bugs, then it would be best to create a new thread for each one.

New user > Try to login w/ incorrect details // EDIT: First failures = You have entered an invalid username or password combination. @/bb/member.php

If you have forgotten your password please retrieve a new one. >> Once the limit is reached you get redirected (again) to /bb/member.php

and one of these three things happens:

~40-45%% of the time

1) "You have failed to login within the required number of attempts.
You must now wait 0h 15m 0s before you can login again."

(Note: This waiting period can be avoided by clearing your cookies)

~40-45%% of the time

2) You see this, without the Captcha

[Image: lock.gif]


or

Very few times (during my tests)

3) The new Captcha shows in the right place
#
MyBB is the best forum software! Exclamation

#27
(12-04-2008, 10:15 PM)seeker Wrote:  1) "You have failed to login within the required number of attempts.
You must now wait 0h 15m 0s before you can login again."

(Note: This waiting period can be avoided by clearing your cookies)

There's no way we can fix that properly. You'll find the same thing with every other forum.

(12-04-2008, 10:15 PM)seeker Wrote:  2) You see this, without the Captcha

[Image: lock.gif]

I'll look into it
#28
(12-04-2008, 10:20 PM)Ryan Gordon Wrote:  I'll look into it

Thanks, Ryan.
One tip on reproducing is to try the correct login details right after you reach the limit of failures.
Continued attempts with the wrong details seem more likely to produce...

"You have failed to login within the required number of attempts.
You must now wait 0h 15m 0s before you can login again."
#
MyBB is the best forum software! Exclamation

#29
Try this:


Attached Files
.php   member.php (Size: 53.98 KB / Downloads: 1,773)
#30
pls tell what you changed
[Image: 350x19.jpg][Image: tstargermany.png]


Forum Jump:


Users browsing this thread: 1 Guest(s)