[wordpress插件] Disallow Pwned Password禁止输入密码

wordpress 插件 文章 2020-04-18 22:41 624 0 全屏看文

AI助手支持GPT4.0

评分
100
描述

Disallow WordPress and WooCommerce users using pwned passwords.

禁止使用自带密码的WordPress和WooCommerce用户。

Goal

目标

Spoiler Alert: User passwords never leave your server, not even in hashed form.

剧透警报:用户密码永远不会离开服务器,即使是散列形式也不会离开

Although reusing passwords is solely users’ fault but when evil attackers brute forced users’ passwords, and stole all their personal information or spent users’ hard earn money through your site.

虽然重用密码完全是用户的错,但是当邪恶的攻击者粗暴地强迫用户输入密码,并偷走了他们的所有个人信息或用过的用户的辛苦赚钱后,您的网站就会被盗。

Those lazy users blame you, the site owner/developer.

那些懒惰的用户责怪您(网站所有者/开发者)。

When processing requests to establish and change memorized secrets, verifiers SHALL compare the prospective secrets against a list that contains values known to be commonly-used, expected, or compromised.

当处理请求以建立和更改存储的机密时,验证者应将预期机密与包含已知通常使用,预期或泄露的值的列表进行比较。

For example,…

例如,...

This plugin's solely purpose is to disallow WordPress and WooCommerce users reusing passwords listed in Have I Been Pwned database

此插件的唯一目的是禁止WordPress和WooCommerce用户重复使用已被我拥有数据库中列出的密码

.

Usage

用法

Activate and forget.

激活并忘记。

This plugin intercepts when:

此插件在以下情况下拦截:

下载地址
https://downloads.wordpress.org/plugin/disallow-pwned-passwords.0.3.2.zip
-EOF-

AI助手支持GPT4.0