Account Lock in Web Mail

Post your MailEnable suggestions here.
Post Reply
rfwilliams777
Posts: 1321
Joined: Thu Nov 11, 2004 5:26 pm
Location: Kingsville, Texas

Account Lock in Web Mail

Post by rfwilliams777 » Wed Oct 24, 2012 8:17 pm

As a security measure, I have ME set to lock a user's account if the user and password is incorrect after so many tries. However, the web mail (when trying to log in) says "Disabled/Unknown User". Can you change just that error message for the account lock to something like "Your account has been locked for 60 minutes" or something more meaningful?
Robert Williams, Owner
www.WWSHosting.net
#1 in MailEnable Business-Class Email Hosting - Switch to Williams Web Solutions and get your first 2 months FREE!
We can be hired to help you with your Mail Enable server, too!

oscar.lamattina
Posts: 11
Joined: Fri Apr 06, 2012 11:12 pm

Re: Account Lock in Web Mail

Post by oscar.lamattina » Wed Nov 14, 2012 8:18 pm

Agree!

MailEnable
Site Admin
Posts: 4441
Joined: Tue Jun 25, 2002 3:03 am
Location: Melbourne, Victoria Australia

Re: Account Lock in Web Mail

Post by MailEnable » Thu Nov 15, 2012 1:48 pm

I actually think this used to be the case in earlier versions of MailEnable - but it was changed.

The reason it was changed was that returning that message would cause a security weakness.

ie: By providing this message to a would-be hacker, you are effectively telling them that they have guessed a valid username.

It could be made to be configurable though and I have raised a suggestion to that effect.
Regards, Andrew

Post Reply