plugin-icon

No User Enumeration

Door Carlos·
Stop user enumeration for security.
Versie
1.3.2
Actieve installaties
200
Laatst bijgewerkt
Oct 23, 2019

In many WordPress installations is possible enumerate usernames through the author archives, using urls like this:

http://wpsite/?author=1

http://wpsite/?author=1/

http://wpsite/?bypass=1&author%00=1

http://wpsite/?author%00=%001

http://wpsite/?%61uthor=1

And recently wordpress since 4.7 comes with a rest api integrated that allow list users:

curl -s http://wpsite/wp-json/wp/v2/users/ curl -s http://wpsite/?rest_route=/wp/v2/users curl http://wpsite/?_method=GET -d rest_route=/wp/v2/users

Know the username of a administrator is the half battle, now an attacker only need guest the password. This plugin stop it.

Also, is possible get usernames from the post entries. This plugin, hide the name of the author in a post entry if he is not using a nickname. Also, hide the url page link of an administrator author.

The main goal is hide the administrators usernames. Obviously, is better not choose “admin” as the username because is easiliy guessable.

Gratisop Business abonnement
Door te installeren, ga je akkoord met de Servicevoorwaarden van WordPress.com en de voorwaarden voor plugins van derden.
Getest tot
WordPress 5.2.23
Deze plugin kan worden gedownload, zodat je hem op je kan gebruiken.