Uploaded image for project: 'Hippo CMS'
  1. Hippo CMS
  2. CMS-3672

Security improvements login page

    XMLWordPrintable

Details

    • Improvement
    • Status: Closed
    • High
    • Resolution: Fixed
    • None
    • 2.22.04, 2.23.02-alpha
    • None

    Description

      • do not mention the version at the login page. This gives hackers more information about vulnerabilities. Instead show versio nr inside the CMS (not too deep please - e.g. not system/admin page)
      • do not show message that a user is already logged in and will be logged out. This provides information about valid user names. Instead when clicking OK ask for conformation to proceed if user is already logged in and passed in credentials are valid.
      • add metatag like <META NAME="ROBOTS" CONTENT="NOINDEX, NOFOLLOW"> (to be verified) to the login page so robots won't pick it up.

      Attachments

        Activity

          People

            mnour Mohammad Nour (Inactive)
            swesten Stephan Westen
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - 1 day, 6 hours Original Estimate - 1 day, 6 hours
                1d 6h
                Remaining:
                Time Spent - 1 day, 45 minutes Remaining Estimate - 6 hours
                6h
                Logged:
                Time Spent - 1 day, 45 minutes Remaining Estimate - 6 hours
                1d 45m