內容簡介
如果您登錄 WordPress 的後台,輸入正確的用戶名但錯誤的密碼,WordPress 會顯示錯誤消息“ERROR: The password you entered for the username admin is incorrect. Lost your password?”,透露了用戶名“admin”被註冊,可能的攻擊者可以使用此用戶名檢查密碼以獲取訪問權限。
這個外掛程式會在您輸入未註冊的用戶名和/或錯誤的密碼時更改錯誤消息為“ERROR: Invalid user/password combination.”,並且增強了您的博客密碼的安全性,讓攻擊者更難破解。
開發者團隊
原文外掛簡介
If you log-in to your WordPress backend and enter the right username but a false
password WordPress shows the error message “ERROR: The password you entered for
the username admin is incorrect. Lost your password?” revealing that the username
“admin” is registered and a possible attacker can check passwords with this
username to gain access to the installation.
This plugin changes the error messages to “ERROR: Invalid user/password
combination.” if you enter a non-registered username and/or a false password and
makes it more difficult for an attacker to decypher your blog’s passwords.
