[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Small Bug

login> login alanp
login: alanp: Unknown user
login> login alan

This isn't a good idea security-wise.  Instead of the 'User
Unknown' error, it should just ask for the password and error
out with an Invalid Password error.  The way it is setup now
it could be used to guess login names, which is pretty much the
reason that most ftpds ask for a password if there is no such
username on the system anyways, now.

Alan P. Laudicina

|          Alan P. Laudicina / alanp@linux.com          |
|  http://corp.linux.com  /  http://www.unixpower.org   |
| "You can get more with a kind word and a gun than you |
| can with a kind word alone." - Al Capone (1899-1947)  |

Reply to: