• Home
  • Geocoding
  • Nieuws
  • Contact
pbackus.com
  • Home
  • Geocoding
  • News
  • Contact
  • Home
  • Geocoding
  • News
  • Contact

WordPress changing the admin-ID or hide author pages?

internet, wordpress|16 oktober 2014
WordPress changing the admin-ID or hide author pages?

In wordpress you can easily change the admin id to a name which is less hackable. But did you know this is of no use unless you have a huge user database with loads of dummy users in which you can hide your admin?

I have seen many video’s and instructions telling you to create a new admin, login and delete the old admin. Video’s that instruct you to create a admin with a name like ‘youdonotfindme’. Plugins like “Better WP Security” suggesting you to change the id and name. And they are all right to some extend. But the thing is that as long as your author pages can be called and you wrote articles with the admin username they are able to find you!! (even if the admin did not write a single article).

Did you know you can call any wordpress website like this?

http://yourwebsite.com/?author=1

if you vary the 1 into 2,3,4,5, etc it will at some moment show you all articles written by that author/user id. If you only have one user they will have the adminname as it is revealed in that simple call to your website and they only need the next step: the password.

The only way to hide it is to have loads of users with no permissions and each with its own lengthy dummy password. So when they find a name and they hack it, they still can’t do anything as the user has no rights. They will get bored by trying to hack you as each cracked password will bring them into a user area with no permissions. Unless they really hit the admin-id of course.

But with a login detection plugin like “login lockdown” you have already discovered what is going on and you are way ahead of them

Top
Hide your author pages plugin.
But what if you dont want to create a load of users and hide your admin? What if you only have one admin with a fancy loginname and you still want to hide it? Just disable the author call to your website is the solution. There is a nice plugin you can use for that which redirects those calls to the root or any custom url of your desire. The plugin is called “Disable Author Pages” And can be downloaded at wordpress.org.

Download the plugin : disable author pages

After installing it and enabling it goto to its settings and enable the redirecting (see image below). Once done nobody can call any author pages anymore and thus revealing the admin name by accident. This will only work if you dont want people to see what author wrote what articles and call his list of written documents. I don’t mind as i never intended to have this ability in my blog anyway. I am the only author, so who cares? I don’t!

Disable your author pages preventing wordpress from revealing admin login names
The Disable Author Pages Plugin
The best thing todo if you want to have your author pages called.

  • Create loads of empty users with a dummy password and no articles attached to them and no permission.
  • Create a author which you use to write all your articles
  • Move your admin user so its hidden within the rest of the users and make sure it has also no articles attached. This way it will look the same as any dummy user they call.
Top
Side note : In any wordpress version it is possible to get a valid loginname by trial and error by the use of the login screen.

What happens that in case you enter a wrong username that username is removed after the login attempt. However if you enter a correct username that username stays visible in the login screen.

Both attempts provide also a different error message explaining that you either provided the wrong username and or password or the wrong password. In the latter case you entered the valid and correct username and indirectly wordpress tells you this (stupid if i may say so).

So besides hiding the author pages one can still get hold of a valid loginname this way.

How to fix that you can read here : WordPress revealing user loginname by trial and error

Top
5 september 2020 admin-pbc

Latest News

  • WordPress  revealing username by login trial and error
    WordPress revealing username by login trial and error

    How to deal with this? 1) We have to tell WordPress a different error message on...

News

  • WordPress  revealing username by login trial and error
    WordPress revealing username by login trial and error 16 oktober 2014

Calender

mei 2025
M D W D V Z Z
 1234
567891011
12131415161718
19202122232425
262728293031  
  « okt    

Contact ons

Intro text

The Phone number

Cell Phone

Faximile

email*theworld.com

Address

City, State Zip

Name

  • Home
  • Geocoding
  • Nieuws
  • Contact
Copyright © 2014 MyCompany.com. All Rights Reserved