Disable Users Enumeration checked, new user name discovered
-
Setup All In One WP Security on a new site.
Activated the basics including ‘Login Lockdown’ ‘instantly lockout non existing user names’ and ‘Disable Users Enumeration’.
Did a simple author URL check and get the response “Accessing author info via link is forbidden” so enumeration seems to be blocked.
Created a new admin user with non-standard name, switched to that user and deleted the old admin user account (also a non-standard name).Looking at “Failed Login Records”, attempts on the old admin username stopped within a few hours and within about 12 hours of creating the new user, that name shows in the Failed Login Records list 459 times!
Obviously there is another external way to discover user names.
As a side note I have:
‘Time Length of Lockout’ set to 44000 which is roughly a month.
‘Completely Block Access To XMLRPC’ is checked:Thoughts?
- The topic ‘Disable Users Enumeration checked, new user name discovered’ is closed to new replies.