<-------------------------Subsonic Help Request---------------------->
Problem Description: I've searched around (see viewtopic.php?f=3&t=1830), and please correct me if I'm wrong, but there doesn't appear to be any way to limit login attempts with Subsonic. This seems like a huge security vulnerability to me. Is there a log of authentication attempts or a way to limit the amount of unsuccessful logins? With the server internet facing in order to use the mobile client, I am shocked to see such a lack in security. Is it even possible to disable admin logins?
Troubleshooting Steps: Anyone can brute force http://<yourdomain.com>[:port]/[context_url/]login.view?user=admin&password=password to get access.
Subsonic Version: 4.7 (build 3105) – September 11, 2012
Server Version: jetty-6.1.x, java 1.6.0_24, Linux (45.0 MB / 90.2 MB)
<-------------------------Subsonic Help Request---------------------->
