1
0
Fork 0
mirror of https://we.phorge.it/source/phorge.git synced 2024-11-10 00:42:41 +01:00
phorge-phorge/externals
epriestley 02aa193cb0 Add a common password blacklist
Summary:
Fixes T4143. This mitigates the "use a botnet to slowly try to login to every user account using the passwords '1234', 'password', 'asdfasdf', ..." attack, like the one that hit GitHub.

(I also donated some money to Openwall as a thanks for compiling this wordlist.)

Test Plan:
  - Tried to register with a weak password; registered with a strong password.
  - Tried to set VCS password to a weak password; set VCS password to a strong password.
  - Tried to change password to a weak password; changed password to a strong password.

Reviewers: btrahan

Reviewed By: btrahan

CC: aran, chad

Maniphest Tasks: T4143

Differential Revision: https://secure.phabricator.com/D8048
2014-01-23 14:01:18 -08:00
..
amazon-ses Fix undefined property in Amazon SES 2013-11-26 12:52:38 -08:00
balanced-php
diff_match_patch Phragment v0 2013-12-07 12:43:49 +11:00
httpful
JsShrink
mimemailparser
phpmailer
recaptcha
restful
s3
skins/oblivious Provide clearer syntax highlighting for phame posts. Including background colour, overflow scrolling and border. Also support for tt tag differentiation 2013-07-03 06:25:45 -07:00
stripe-php
vegas
wepay Strip +x from some WePay files 2013-11-12 17:48:47 -08:00
wordlist Add a common password blacklist 2014-01-23 14:01:18 -08:00
xhprof