[TYPO3-english] Typo3 BE login security

Marcus Krause marcus#exp2010 at t3sec.info
Thu Mar 25 06:40:40 CET 2010


Pero Matic schrieb am 03/24/2010 10:46 PM Uhr:
> Hi. I'm interested how do you guys protect access to BE from u/p brute force 
> attacks etc.?

* by usage of an additional authentication service (openid) and setting
the BE user password to an arbitrary complex & lengthy string (won't be
used anyway with openid)
* by usage of TYPO3 IP filter (whitelisting)


Both methods are available in TYPO3 (4.3) by default.

Marcus.


More information about the TYPO3-english mailing list