Banner for Baw Breach Avoider
Avoid to be easily the target of the HTTPS BREACH vulnerability. Wordpress Tutorial
Noted That:
  • To install correctly this baw-breach-avoider.zip .
  • Fisrt Download the baw-breach-avoider.zip to your computer
  • Extract/Open baw-breach-avoider.zip to Your Computer.
  • Then, Find readme.txt file inside baw-breach-avoider.zip and Open readme.txt .
  • Now, Read the Requirements of this plugin. Which Wordpress Version and PHP Version are required to run this Plugin in Your Wordpress Site.
  • Then, Follow the Tips Below.
Start the Tips:

Step-1 : Download " baw-breach-avoider.zip " to Your Local Computer.

Step-2 : Then, Login to your " yourdomain.com/wp-admin " Dashboard.

Login to Wordpress Baw Breach Avoider

Step-3 : Then, Click on " Plugins " + " Add New " from left Side Menu of Dashboard.

Go to Plugin Install Baw Breach Avoider

Step-4 : Now, Click on " Upload Plugin " button.

Click Upload Button Baw Breach Avoider

Step-5 : Now, Browse " baw-breach-avoider.zip " Downloaded plugin from your computer, Where you downloaded " baw-breach-avoider.zip " According to Step – 1 Above then, click on " Install Now "

Upload Plugin Baw Breach Avoider

Step-6 : Now, Click on " Active Plugin "

Activate Baw Breach Avoider

Step-7 : Then, See left Side Menu. " Baw Breach Avoider " folder is added on left Side Menu. Now, Click on " Baw Breach Avoider " folder.

Noted that: If you do not see " Baw Breach Avoider " folder on left Side Menu then, see at left Side Menu " Settings " or " Tools ".

Step-8 : Now you configure yourself oR Watch video tutorial below about Baw Breach Avoider Configurations and Settings or How to work " Baw Breach Avoider " in your WordPress site.

oR

After Activated Plugin According to Step-6 then,

  1. Go to " Plugins " + " Installed Plugin " from Wordpress Admin Panel Leftside Menu.
  2. or Direct go to: https://yourdomain/wp-admin/plugins.php
  3. Then, Find " BREACH Avoider " Activated Plugin from Plugin List.
  4. Then, Click on " Settings " from Plugin that is BREACH Avoider
  5. Now, Edit/Add/Config the setting and Click on " Save Changes " button,
WP Plugin Setting



Guide
  1. Extract the plugin folder from the downloaded ZIP file.
  2. Upload Bthe folder to your /wp-content/plugins/ directory.
  3. Activate the plugin from the “Plugins” page in your Dashboard.
  4. Done!

You can (and i encourage you to do it) define 2 constant in wp-config.php file :

BBA_REPEATER : used by this plugin to add a new secret srting in each nonces (e number used once to create a secure token and avoid CSRF flaws), default is 2, min is 1, no max, just change it.

BBA_NONCE_LENGTH : From 4 to 32 with 10 for default value, you can modify the length the each nonces in WordPress, the longer, the better

Also, WordPress includes a “nonce_life” filter hook. Its default value is 1 day, i suggest you to low this value, like 12 hours or 6 hours (DAY_IN_SECONDS /2 or /4)


Name