plugin-icon

Super Simple Account Enumeration Blocker

제작자: Paul Gilzow·
Blocks account enumeration attempts
버전
1.0.0
최근 업데이트일
Apr 17, 2017

After speaking at WordCamp St. Louis 2017 http://wordpress.tv/2017/03/29/paul-gilzow-access-denied-keeping-yourself-off-an-attackers-radar/, I was asked if I could bundle the code I demo’ed in the talk into a plugin for people who aren’t as comfortable writing their own code. As its name implies, it is super simple. There are no settings. The entire codebase is contained in one file, and for the most part is about 20 lines of code in length. It is fully commented and I encourage you to look at the code to see what it does instead of blindly trusting it.

Specifically, this plugin: * removes the redirection of a request from /?author=# to an author’s pretty permalink * changes author pretty permalinks to /?author=# * changes author feed pretty permalinks to /?author=#&feed= * removes author slug property from user response object for user endpoint in the REST API * removes overly informative error message when login attempt fails

Rememer: this plugin, by itself, will not protect your site from being compromised. However, it can be an important layer of defense when used in a multilayer, defense-in-depth security strategy.

Help and Support

Please post questions, request for help to the WordPress plugins forum or email ssaeb@gilzow.com. Please be sure to include ‘ssaeb’ in the subject line.

TO-DO’s

Keep adding ways to block enumerations.

무료Business 요금제에서
설치하면 WordPress.com 서비스 약관서드파티 플러그인 약관에 동의하게 됩니다.
테스트된 버전
WordPress 4.7.31
이 플러그인은 다운로드할 수 있으며 에서 사용할 수 있습니다.