plugin-icon

Prevent user name and email leakage

投稿者: Mark-k·
Stops user name enumeration and other type of user name and email leakages.
バージョン
1.0.0
最終更新日時
Apr 22, 2018

Stops user name enumeration and other type of user name and email leakages.

Specifically does the following: 1. When the site is configured to use pretty permalinks, the plugin will prevent the automatic redirect of usrl which include user ID, like example.com/?author=1, to something like example.com/author/admin which will leak the existence of a user named admin which can be used in further brute force attacks. (This is also know as “user enumeration”).

  1. With the REST API restrict user name related information (actual user name and user posts page URL) to only admin users.

  2. Preventing authentication failure notices on the login page to disclose the existence of user names/user emails resulting from displaying different messages hen the user is incorrect and when the password is incorrect. Just display the same failure message for whatever is the failure reason.

  3. Preventing the reset password mechanism from disclosing user names/user emails resulting from displaying different messages when a user/email for which a reset is requested exist in the DB, and when it does not. Just display the same message for both.

Even with the plugin active, if your theme displays author information while linking to author pages this can be used for user name leakage. In this case you should think about totally decoupling user and author information with plugins like https://wordpress.org/plugins/authors-as-taxonomy/

Another thing that the plugin do not do is to handle leakage resulting from the use of gravatar, as this requires a replacement of gravatar functionality itself and it is much harder to exploit than the other leakages.

And last leakage hole not covered right now, but might be covered in the future, is leakage of information via the sign in process. We leave it for later as most installs do not allow people to sign in.

Read more on the plugins main page https://calmpress.org/wordpress-plugins/prevent-user-name-and-email-leakage/

Documentation

Contribute

Pull Requests, bug reports and/or enhancement suggestions are welcome at https://github.com/calmPress/Authors-as-taxonomy

無料有料プラン
インストールすることで、WordPress.com の利用規約サードパーティプラグイン利用規約に同意したことになります。
最大テスト回数
WordPress 4.9.29
このプラグインをダウンロードして、 サイトに使用できます。