I'm not sure how using session to store the invalid attempt count works, but it's sounding like a DoS waiting to happen. What if I (not legit user) want to stop you (legit user) from accessing your account? I guess I could try three times to get your password (and get it wrong). Then you (legit user) will be locked out of your own account :icon_eek:
Comatose 290 Taboo Programmer Team Colleague
iamthwee commented: Erebus, wtf is up with rick ashley arrrrgh!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! -4
cikara21 commented: haha.. +1
Comatose 290 Taboo Programmer Team Colleague