1
0
Fork 0
mirror of https://we.phorge.it/source/phorge.git synced 2024-09-20 01:08:50 +02:00
phorge-phorge/externals
epriestley 02aa193cb0 Add a common password blacklist
Summary:
Fixes T4143. This mitigates the "use a botnet to slowly try to login to every user account using the passwords '1234', 'password', 'asdfasdf', ..." attack, like the one that hit GitHub.

(I also donated some money to Openwall as a thanks for compiling this wordlist.)

Test Plan:
  - Tried to register with a weak password; registered with a strong password.
  - Tried to set VCS password to a weak password; set VCS password to a strong password.
  - Tried to change password to a weak password; changed password to a strong password.

Reviewers: btrahan

Reviewed By: btrahan

CC: aran, chad

Maniphest Tasks: T4143

Differential Revision: https://secure.phabricator.com/D8048
2014-01-23 14:01:18 -08:00
..
amazon-ses Fix undefined property in Amazon SES 2013-11-26 12:52:38 -08:00
balanced-php Add Balanced Payments API 2013-04-25 09:47:30 -07:00
diff_match_patch Phragment v0 2013-12-07 12:43:49 +11:00
httpful Add Balanced Payments API 2013-04-25 09:47:30 -07:00
JsShrink Use JsShrink if jsxmin is not available 2013-05-18 17:04:22 -07:00
mimemailparser Skip attaching 'inline' text attachments 2011-06-12 22:38:57 -07:00
phpmailer Use ExecFuture to raise sendmail error codes out of PHPMailer 2013-03-30 15:51:32 -07:00
recaptcha
restful Add Balanced Payments API 2013-04-25 09:47:30 -07:00
s3 Update S3 external library 2013-07-02 18:55:08 -07:00
skins/oblivious Provide clearer syntax highlighting for phame posts. Including background colour, overflow scrolling and border. Also support for tt tag differentiation 2013-07-03 06:25:45 -07:00
stripe-php For discussion -- Stripe integration 2012-04-04 16:09:29 -07:00
vegas
wepay Strip +x from some WePay files 2013-11-12 17:48:47 -08:00
wordlist Add a common password blacklist 2014-01-23 14:01:18 -08:00
xhprof Fix some issues caught by HipHop, and work around some issues 2011-02-26 21:01:42 -08:00