이 플러그인은 최근 3개의 주요 워드프레스 출시와 시험 되지 않았습니다. 워드프레스의 좀 더 최근 버전으로 이용할 때 더 이상 관리되지 않고 지원되지 않고 호환성 문제가 있을 수 있습니다.

Prevent user name and email leakage

설명

Stops user name enumeration and other type of user name and email leakages.

Specifically does the following:
1. When the site is configured to use pretty permalinks, the plugin will prevent
the automatic redirect of usrl which include user ID, like example.com/?author=1, to
something like example.com/author/admin which will leak the existence of a user
named admin which can be used in further brute force attacks.
(This is also know as “user enumeration”).

  1. With the REST API restrict user name related information (actual user name
    and user posts page URL) to only admin users.

  2. Preventing authentication failure notices on the login page to disclose
    the existence of user names/user emails resulting from displaying different
    messages hen the user is incorrect and when the password is incorrect. Just
    display the same failure message for whatever is the failure reason.

  3. Preventing the reset password mechanism from disclosing user names/user emails
    resulting from displaying different messages when a user/email for which a reset
    is requested exist in the DB, and when it does not. Just display the same message
    for both.

Even with the plugin active, if your theme displays author information while linking
to author pages this can be used for user name leakage. In this case you should
think about totally decoupling user and author information with plugins like
https://wordpress.org/plugins/authors-as-taxonomy/

Another thing that the plugin do not do is to handle leakage resulting from the use
of gravatar, as this requires a replacement of gravatar functionality itself and
it is much harder to exploit than the other leakages.

And last leakage hole not covered right now, but might be covered in the future,
is leakage of information via the sign in process. We leave it for later as most
installs do not allow people to sign in.

Read more on the plugins main page https://calmpress.org/wordpress-plugins/prevent-user-name-and-email-leakage/

Documentation

Contribute

Pull Requests, bug reports and/or enhancement suggestions are welcome at https://github.com/calmPress/Authors-as-taxonomy

후기

이 플러그인에 대한 평가가 없습니다.

기여자 & 개발자

“Prevent user name and email leakage”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이 플러그인에 기여하였습니다.

기여자

자국어로 “Prevent user name and email leakage”(을)를 번역하세요.

개발에 관심이 있으십니까?

코드 탐색하기는, SVN 저장소를 확인하시거나, 개발 기록RSS로 구독하세요.

변경이력

1.0.0 – December 25th 2017

  • Initial release