Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 06-21-2010, 12:18 AM
Elite Member
 
Posts: 296
Default captcha support for webmail interface?

Dear all,

is it possible to have captcha support when users login via Webmail interface?

thanks.
Reply With Quote
  #2 (permalink)  
Old 06-21-2010, 12:25 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by tiger2000 View Post
is it possible to have captcha support when users login via Webmail interface?
Not unless you implement it or file an RFE in Bugzilla Main Page - Zimbra. Why do you think you need it? The implementation of good password policies should obviate the need for using captcha.
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 06-21-2010, 06:24 PM
Starter Member
 
Posts: 1
Default

The account locking mechanism will cause DoS when the hacker is guessing the password. I think CAPTCHA is a better solution.

Regards,
Eric
Reply With Quote
  #4 (permalink)  
Old 06-22-2010, 01:57 AM
Partner (VAR/HSP)
 
Posts: 260
Default

CAPTCHA would impose a very annoying restriction on normal users.
You would be able to build something yourself I would imagine with a php app and authenticated reverse proxy anyway if you like.
__________________
http://www.solutionsfirst.com.au/hosting/zimbra/
Australia's premier Zimbra Hosting Partner
Resellers wanted!
Reply With Quote
  #5 (permalink)  
Old 06-23-2010, 11:39 PM
Elite Member
 
Posts: 296
Default

could you please elaborate some details on how to build that with a php program? any other reference/document i can check?

thanks in advance.
Reply With Quote
  #6 (permalink)  
Old 06-24-2010, 02:37 AM
Moderator
 
Posts: 927
Default

There are multiple ways to defeat most captcha systems, and they offer a different type of protection to the auto password lock system.

If someone is tryingto brute force one of your accounts, then having it lock out lets you know that something is amiss, the main admin shouldnt just go to the admin console and unlock the account, they should work out WHY the account was locked. Was it the user themselves keying in the password wrong, or was it a hacking attempt. The information gathered from that check is powerful.

If someone is trying to brute force an account, and in addition to the username and password they need a captcha, then it's not likely to stop them, they could brute force the captcha or send it's details out to services that deal with them.

If you do go ahead and impliment such a system, you'd need to be pretty secure in two things;
1, that your code is good enough to always work, every time, no exceptions. You dont want a user to be keying everything in correcty and still be unable to connect,
2, that the captcha system you use is unbreakable, you dont want to go to all this effort for a system thats trivial to defeat.

I cant offer any help with the actual coding, but I'd imagine you could simply hijack the login process to show your own login system which would, once authenticate, call Zimbra's pre-authentication mechanisms to then automatically log the user in, there's lots of detail on this in the wiki's.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.