Banned: XXX.XXX.XXX.XXX for failing honeypot_time on user_pass

Created on 18 March 2024, 9 months ago

Problem/Motivation

We're seeing messages like this:

Banned: XXX.XXX.XXX.XXX for failing honeypot_time on user_pass
Source: https://www.doctor-catch.com/de/user/password
User Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Mobile Safari/537.36

logged by Perimeter.

But there's no honeypot configuration (duration) and no way to disable it and only use perimeter blocking for the patterns defined.
So I'm wondering about the reason?

I didn't have a look at code, but this seems to block users very fast. We should find out how and why this happens in code and if we need to add further configuration for this.

Steps to reproduce

TODO

Proposed resolution

Remaining tasks

User interface changes

API changes

Data model changes

πŸ“Œ Task
Status

Active

Version

3.0

Component

Code

Created by

πŸ‡©πŸ‡ͺGermany Anybody Porta Westfalica

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Production build 0.71.5 2024