/srv/irclogs.ubuntu.com/2022/01/20/#xubuntu-devel.txt

=== genii is now known as genii-meeting
tomreynknome: about wordpress user 1 / "admin", I agree, chaging the username does notreally help, i just mentioned it as a strategy that was suggested at some point. it does seem better to delete user with id 1 and create a new one, not named "admin".00:10
knometomreyn, indeed. though again, the user ID is what counts, because that's the one which is used when checking permissions00:11
knome(even though usernames still need to be unique and can't be changed..)00:11
tomreynand thus could, under some circumstances (where username -> user id can be determined), enable an attacker to determine an admnistrative account (for further attacks) easily.00:13
knomeof course00:13
knomebut given that you can't even create an account named admin as the second account as that is already taken.. :)00:14
knomeanyway, time to prepare for bed00:15
tomreyneven if it's deleted? ok, i didn't know that00:15
knomenighty everybody :)00:15
knomewell00:15
knomeit can't be deleted00:15
knomeif you only have one user00:15
knomeand are creating the other one00:15
tomreynright, sleep well00:16
knomeyou'd first have to create and admin user for ID 2, then delete ID 1, *then* create *another* admin user for ID 3+, with the username admin00:16
knomeso yes, that's technically possible, but i don't know why somebody would go through that struggle if they intend to use a dumb username after all :P00:16
knomebut fair point, also don't use "sausage" as your password00:17
knome:D00:17
knomenighty!00:17
=== genii-meeting is now known as genii
=== genii is now known as genii-core
=== Baytuch_2 is now known as Baytuch
=== DarkTrick_ is now known as DarkTrick
=== edun is now known as qbt
Baytuchhi08:54
=== genii-core is now known as genii

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!