Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Views Bootstrap 5.5.4 — Minor update available for module views_bootstrap (5.5.4). Release: Rightup theme 1.0.3 — Minor update available for theme vartheme_bs5_rightup (1.0.3). Release: CommentOn 1.0.6 — Minor update available for module commenton (1.0.6). Release: ChatGPT Ads 1.0.3 — Minor update available for module chatgpt_ads (1.0.3). Release: Opensolr Search 5.1.3 — Minor update available for module opensolr_search (5.1.3). Release: ServiceM8 Webform Integration 1.2.1 — Minor update available for module servicem8_webform (1.2.1). Release: PostfixAdmin 1.0.0 — Initial release available for module postfix_admin (1.0.0)! Release: ip_analyser 1.0.3 — Minor update available for module ip_analyser (1.0.3). Module Revived: Swagger-PHP OpenAPI 3 documentation generator 1.0.0 — Module swagger_php updated after 10 months of inactivity (1.0.0). Security Coverage: Microsoft Azure AI — Module ai_provider_azure now has official Drupal security advisory coverage.

Username Enumeration Prevention is a project which aims to mitigate common ways of anonymous users identifying valid usernames on a Drupal 8+ site.

What Is Username Enumeration?

Username enumeration is a technique used by malicious actors to identify valid usernames on a web application, which can then be used in other attacks such as credential stuffing.

What does Username Enumeration Prevention do?

  • Provides warnings on admin status report if site is configuration could expose usernames
  • Prevents password reset form from displaying the following messages
    • '%name is blocked or has not been activated yet.'
    • '%name is not recognized as a username or an email address.'
  • Converts 403 Access Denied responses to 404 Not Found on user profiles.

Drupal 7 Note: If you're using Drupal 7.83 or above, you can safely remove this module, as its functionality have been brought into core

Additional Notes

Enabling this module is one step to preventing the usernames on the system from being found out but there are other known methods that are just as easy.

  • If a user belongs to a role that has "access user profiles" granted to it, then that user can serially visit all integers at the URL http://drupal.org/user/UID and get the username from the loaded profile pages.
  • "submitted by" information on nodes or comments, views, exposed filters or by other contributed modules can also expose usernames. Site builders looking to hide usernames from comments and nodes should look at using realname or some other tool.
  • Browser autocompletion on the user login page can be disabled using the Security Kit module.
  • The Drupal security team does not consider username enumeration a vulnerability.

Core Issue

Anyone looking to contribute to this project should first review the core issue and see if there is any way they can help push that forward.

Get Started

Composer

  • Add the project to your project's composer dependencies.
    composer require "drupal/username_enumeration_prevention"
  • Navigate to Administer >> Extend.
  • Enable Username Enumeration Prevention.

Manual

  • Place the entirety of the module directory in
    modules/contrib/username_enumeration_prevention.
  • Navigate to Administer >> Extend.
  • Enable Username Enumeration Prevention.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
1
Tracked since
Sep 2024
Latest release
2 years ago
Releases (12 mo)
0
Maintenance
Dormant

Releases

Version Type Core Release date
8.x-1.4 Stable Sep 5, 2024