Version Description
Download this release
Release Info
Developer | llocally |
Plugin | Stop User Enumeration |
Version | 1.2.9 |
Comparing to | |
See all releases |
Code changes from version 1.2.8 to 1.2.9
- readme.txt +6 -2
- stop-user-enumeration.php +11 -8
readme.txt
CHANGED
@@ -3,8 +3,8 @@ Contributors: llocally
|
|
3 |
Donate link: https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=ZEWW5LKK5995J
|
4 |
Tags: User Enumeration, Security, WPSCAN, fail2ban
|
5 |
Requires at least: 3.4
|
6 |
-
Tested up to:
|
7 |
-
Stable tag: 1.2.
|
8 |
License: GPLv2 or later
|
9 |
License URI: http://www.gnu.org/licenses/gpl-2.0.html
|
10 |
|
@@ -43,6 +43,10 @@ Adjusted to your own requirements.
|
|
43 |
=
|
44 |
= 1.2.8 =
|
45 |
|
|
|
|
|
|
|
|
|
46 |
* allow comments to use author in url
|
47 |
|
48 |
= 1.2.7 =
|
3 |
Donate link: https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=ZEWW5LKK5995J
|
4 |
Tags: User Enumeration, Security, WPSCAN, fail2ban
|
5 |
Requires at least: 3.4
|
6 |
+
Tested up to: 4.0
|
7 |
+
Stable tag: 1.2.9
|
8 |
License: GPLv2 or later
|
9 |
License URI: http://www.gnu.org/licenses/gpl-2.0.html
|
10 |
|
43 |
=
|
44 |
= 1.2.8 =
|
45 |
|
46 |
+
* bug fix to allow comments to use author in url
|
47 |
+
|
48 |
+
= 1.2.8 =
|
49 |
+
|
50 |
* allow comments to use author in url
|
51 |
|
52 |
= 1.2.7 =
|
stop-user-enumeration.php
CHANGED
@@ -3,7 +3,7 @@
|
|
3 |
Plugin Name: Stop User Enumeration
|
4 |
Plugin URI: http://llocally.com/wordpress-plugins/stop-user-enumeration
|
5 |
Description: User enumeration is a technique used by hackers to get your login name if you are using permalinks. This plugin stops that.
|
6 |
-
Version: 1.2.
|
7 |
Author: llocally
|
8 |
Author URI: http://llocally.com/wordpress-plugins/
|
9 |
License: GPLv2 or later
|
@@ -28,18 +28,21 @@ Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
|
|
28 |
|
29 |
|
30 |
if ( ! is_admin()){
|
31 |
-
if (!
|
32 |
-
|
33 |
-
|
|
|
|
|
|
|
34 |
|
35 |
if(preg_match('/author=([0-9]*)/', $_SERVER['QUERY_STRING']) === 1)
|
36 |
ll_kill_enumeration();
|
37 |
|
38 |
-
// If isn't admin, requested URI isn't wp-comments-post and $_POST['author']
|
39 |
-
if(preg_match('/(wp-comments-post)/', $_SERVER['REQUEST_URI']) === 0 && isset($_POST['author']))
|
40 |
-
ll_kill_enumeration();
|
41 |
add_filter('redirect_canonical','ll_detect_enumeration', 10,2);
|
42 |
-
|
|
|
|
|
|
|
43 |
|
44 |
add_filter('redirect_canonical','ll_detect_enumeration', 10,2);
|
45 |
function ll_detect_enumeration ($redirect_url, $requested_url) {
|
3 |
Plugin Name: Stop User Enumeration
|
4 |
Plugin URI: http://llocally.com/wordpress-plugins/stop-user-enumeration
|
5 |
Description: User enumeration is a technique used by hackers to get your login name if you are using permalinks. This plugin stops that.
|
6 |
+
Version: 1.2.9
|
7 |
Author: llocally
|
8 |
Author URI: http://llocally.com/wordpress-plugins/
|
9 |
License: GPLv2 or later
|
28 |
|
29 |
|
30 |
if ( ! is_admin()){
|
31 |
+
if ( ! is_admin()){
|
32 |
+
if(preg_match('/(wp-comments-post)/', $_SERVER['REQUEST_URI']) === 0 ) {
|
33 |
+
if (!empty($_POST[author])) {
|
34 |
+
ll_kill_enumeration();
|
35 |
+
}
|
36 |
+
}
|
37 |
|
38 |
if(preg_match('/author=([0-9]*)/', $_SERVER['QUERY_STRING']) === 1)
|
39 |
ll_kill_enumeration();
|
40 |
|
|
|
|
|
|
|
41 |
add_filter('redirect_canonical','ll_detect_enumeration', 10,2);
|
42 |
+
}
|
43 |
+
}
|
44 |
+
|
45 |
+
|
46 |
|
47 |
add_filter('redirect_canonical','ll_detect_enumeration', 10,2);
|
48 |
function ll_detect_enumeration ($redirect_url, $requested_url) {
|