rejetto forum

No [unauthorized] Page when needed

Guest · 3 · 5591

0 Members and 1 Guest are viewing this topic.

Dutchman01

  • Guest
I got a problem on my page, http://dutchmansftp.go.2mydns.com.

People can login with any fake name and password.
But they lucky can't they get my user/password protected files.

Don't no when the enter a fake name and pass [unauthorized] page does not show up.

This page only shows up when a entered User in Options Users....
Try's to log in with his right user name and wrong password.

Wy doesn't show up when the entered complytly wrong.?


Offline rejetto

  • Administrator
  • Tireless poster
  • *****
    • Posts: 13525
    • View Profile
maybe you know that in hfs you can set user/pwd for each file, you are not limited to user accounts

1. hfs for now doesn't keep track of all those user/pwd, so doesn't know if a login is useful or makes sense. so if the user is not in the user accounts, it just accept it.

2. there is no risk in accepting any login, because this doesn't mean it can access resources

3. there is a little problem in the fact you could have a user account A/B associated to a file, and after setting a user/password A/C for the same file. HFS should accept both passwords, give access to the file, but knowing that they are different identities, because the user account may have more options associated.


anyway, i already planned to change this in next versions, and HFS will accept only logins actually used in the VFS or in user accounts.


Dutchman01

  • Guest
Thanks for your reply,

I Tougt that the fould was in my template glad it isn't.

Great that you will fix it in the next version.