plugin-icon

No User Enumeration

De Carlos·
Stop user enumeration for security.
Versión
1.3.2
Instalaciones activas
200
Última actualización
Oct 23, 2019

In many WordPress installations is possible enumerate usernames through the author archives, using urls like this:

http://wpsite/?author=1

http://wpsite/?author=1/

http://wpsite/?bypass=1&author%00=1

http://wpsite/?author%00=%001

http://wpsite/?%61uthor=1

And recently wordpress since 4.7 comes with a rest api integrated that allow list users:

curl -s http://wpsite/wp-json/wp/v2/users/ curl -s http://wpsite/?rest_route=/wp/v2/users curl http://wpsite/?_method=GET -d rest_route=/wp/v2/users

Know the username of a administrator is the half battle, now an attacker only need guest the password. This plugin stop it.

Also, is possible get usernames from the post entries. This plugin, hide the name of the author in a post entry if he is not using a nickname. Also, hide the url page link of an administrator author.

The main goal is hide the administrators usernames. Obviously, is better not choose «admin» as the username because is easiliy guessable.

Gratiscon el plan Business
Probado hasta
WordPress 5.2.23
Te puedes descargar este plugin para utilizarlo en tu sitio de .