Skip to main content

Use a generic login error message that does not leak personal information

C
Written by Cyberangels
Updated over 2 years ago

This vulnerability highlights how the use of an advanced CMS such as Wordpress, if not properly monitored on a recurring basis, can represent a huge security breach for professionals and companies of all sizes.

In fact, in the event of an attempt to access an administration panel with an incorrect user or password, the system must respond with an error message that does not actually reveal too much information about what is happening in the database behind it.

If you access the page, you try to enter the username 'test' and a random password and get an error message similar to: 'Error: the username test is not registered on this site. If you are not sure of your username, please try your e-mail address instead..". This way you can be sure that that user name is not present.

Once the right username is found, the site becomes prone to brute-force attacks, which are easy to execute.

HOW TO AVOID

Change the error message to a more standard and secure generic message: "We could not find an account that matches the username and password entered.β€―"

Did this answer your question?