Account Lock in Web Mail
-
- Posts: 1370
- Joined: Thu Nov 11, 2004 5:26 pm
- Location: Kingsville, Texas
Account Lock in Web Mail
As a security measure, I have ME set to lock a user's account if the user and password is incorrect after so many tries. However, the web mail (when trying to log in) says "Disabled/Unknown User". Can you change just that error message for the account lock to something like "Your account has been locked for 60 minutes" or something more meaningful?
Robert Williams, Owner
www.WilliamsWebSolutions.com
#1 in MailEnable Business-Class Email Hosting - Switch to Williams Web Solutions and we will migrate your accounts to us for FREE!
We can be hired to help you with your Mail Enable server, too!
www.WilliamsWebSolutions.com
#1 in MailEnable Business-Class Email Hosting - Switch to Williams Web Solutions and we will migrate your accounts to us for FREE!
We can be hired to help you with your Mail Enable server, too!
-
- Site Admin
- Posts: 4441
- Joined: Tue Jun 25, 2002 3:03 am
- Location: Melbourne, Victoria Australia
Re: Account Lock in Web Mail
I actually think this used to be the case in earlier versions of MailEnable - but it was changed.
The reason it was changed was that returning that message would cause a security weakness.
ie: By providing this message to a would-be hacker, you are effectively telling them that they have guessed a valid username.
It could be made to be configurable though and I have raised a suggestion to that effect.
The reason it was changed was that returning that message would cause a security weakness.
ie: By providing this message to a would-be hacker, you are effectively telling them that they have guessed a valid username.
It could be made to be configurable though and I have raised a suggestion to that effect.
Regards, Andrew