Can a system administrator (full access to the server) remove the lock out prematurely?
In my case it's the "root" username. There also is some another user in Administrators group but contacting that person could take more time than those 12 hours (oh, holidays). A quick peek around via MySQL client didn't reveal anything, probably I need full database dumps in a test installation -- but I'm currently not into hacking that deep. It's not critical anyway.
Moreover, is it possible to turn this feature off, or change the number of attempts allowed? Current behaviour of the PacsOne web interface makes denial of service attacks trivial, especially because neither readme.txt nor manual.pdf contain instructions about the fix.
"You have been locked out" (6.3.1)
If you have full access to the server where PacsOne Server is installed, e.g., the System Administrator, you can un-lock a web user by removing the following file under the directory where PacsOne is installed:
Code: Select all
FailedLogin/$username