mirror of
https://we.phorge.it/source/phorge.git
synced 2024-12-15 10:00:55 +01:00
02aa193cb0
Summary: Fixes T4143. This mitigates the "use a botnet to slowly try to login to every user account using the passwords '1234', 'password', 'asdfasdf', ..." attack, like the one that hit GitHub. (I also donated some money to Openwall as a thanks for compiling this wordlist.) Test Plan: - Tried to register with a weak password; registered with a strong password. - Tried to set VCS password to a weak password; set VCS password to a strong password. - Tried to change password to a weak password; changed password to a strong password. Reviewers: btrahan Reviewed By: btrahan CC: aran, chad Maniphest Tasks: T4143 Differential Revision: https://secure.phabricator.com/D8048 |
||
---|---|---|
.. | ||
amazon-ses | ||
balanced-php | ||
diff_match_patch | ||
httpful | ||
JsShrink | ||
mimemailparser | ||
phpmailer | ||
recaptcha | ||
restful | ||
s3 | ||
skins/oblivious | ||
stripe-php | ||
vegas | ||
wepay | ||
wordlist | ||
xhprof |