Wordpress

How to Stop XMLRPC Attack in WordPress

Posted on
XML-RPC Attack
Saw a HTTP attack, it sent 12 to 20 requests per second on /xmlrpc.php, then made web server jam. In HTTP access log, we saw a lot of requests like this: 35.185.90.35 – – [03/Mar/2019:21:35:40 -0500] “POST /xmlrpc.php HTTP/1.1” 200 401 35.185.90.35 – – [03/Mar/2019:21:35:40 -0500] “POST /xmlrpc.php HTTP/1.1” 200 401 35.185.90.35 – – [03/Mar/2019:21:35:40 […]