Lockdown Ledger
Lockdown Ledger
@LockdownLedger

User Enumeration Block SOP

User Enumeration Block SOP
Attackers need a valid username before brute-forcing. Deny them the list.

— Step 1: Block /?author=N redirects — they expose the login slug. Confirm /?author=1 returns 403.
— Step 2: Close the REST users endpoint to anonymous callers (see your REST SOP).
— Step 3: Disable author archive pages if your site has no public author concept.
— Step 4: Verify the login form returns one generic error for both bad username and bad password.
— Step 5: Strip the WordPress version from generator meta and readme.html so attackers can't match CVEs.
— Step 6: Test enumeration with a scanner; a clean run returns zero usernames.

Do this on every public-facing site.
Run this every time.
Этот пост опубликован в Telegram-канале Lockdown Ledger. Подписаться можно по ссылке: @LockdownLedger.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.