Magento连接管理器-Access is locked. Please try again in a few minutes.

As of Magneto 1.9.3 magento have finally added brute force protection to the downloader folder. As you may be aware even if you have changed your default admin path ie to anything other that /admin Magento connection is still accessible at yourdomain.com/downloader. The fix for this is to rename your downloader folder or move it out of the root folder so that it is not accessable. However, in order to use Connect you need to rename and it had a tendancy to be forgotten. This means that the whole of the internet can have as many guesses at your usernames and passwords as they like.

As well as renaming the downloader folder when ever we find it we also run Fail2ban which monitors access to this fodler and will block IP addresses that fail to log in multiple times. However, Magento have now added a similar feature into the core of magento. There is a new file in var/ called brute-force.ini which monitors login attampt to

Connectbrute-force-bad-attempts-count = 6
brute-force-diff-time-to-attempt = 360
brute-force-attempts-count = 3

Of course the downside is that you may find yourself locked out.If you seeAccess is locked. Please try again in a few minutesreset the above

brute-force-bad-attempts-count = 0

and you should be able to log in. We still recommend you remove or rename the downloader folder for more complete secuirty.

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值