Add parameters and null byte to bypass protection
-
Stop User Enumeration protection bypass:
Two bypass techniques have been found:
1. https://wp-target/?asd=qwe&author%00=1
Line 45 of stop-user-enumeration.php: preg_match() string is not properly coded due to which protection bypass takes place.
2. https://wp-target/?author%00=1
If the user has not published any posts on the blog then his username is shown in page response.
Viewing 7 replies - 1 through 7 (of 7 total)
Viewing 7 replies - 1 through 7 (of 7 total)
- The topic ‘Add parameters and null byte to bypass protection’ is closed to new replies.