# Summary
Attackers can easily find usernames that exist by using the forgot password form and a technique called “username enumeration”. The attacker can enter a username that does not exist and they will get a response from Drupal saying so. All the attacker needs to do is keep trying usernames on this form until they find a valid user.
This module will stop this from happening. When the module is enabled, the error message will be replaced for the same message as a valid user and they will be redirected back to the login form. If the user does not exist, no password reset email will be sent, but the attacker will not know this is the case.
# Project URL
https://www.drupal.org/project/username_enumeration_prevention
# Where is the code?
https://www.drupal.org/project/username_enumeration_prevention
# Estimated completion date
# Dependencies
# Who's doing the port?
# What help do they need?
# D8 roadmap
#1521996: Password reset form reveals whether an email or username is in use
# Background and reference information
This module may become obsolete for Drupal 8 if #1521996: Password reset form reveals whether an email or username is in use lands in core.
Comments
Comment #2
mgiffordComment #3
mgiffordComment #4
anavarreThis no longer might be needed: https://www.drupal.org/node/1521996
Comment #5
drummThe security tag is for tracking public security issues on projects that do not fall under the security advisory coverage policy, and security hardening issues.
Comment #6
rootworkTo save people a click, I'll point out that #1521996: Password reset form reveals whether an email or username is in use is still in progress, so I wouldn't say this module is obsolete for D8 yet!
Also updated the IS.
Comment #7
nicksanta commentedJust tagged a 8.x-1.0 release today.
Comment #8
avpadernoI am giving credits to the users who participated in this issue.