Recent new xmlrpc.php brute force password-guessing attack details
-
Our hosting company has recently seen a new kind of attack on the WordPress xmlrpc.php file: a password guessing attack that uses the wp.getUsersBlogs feature. This is different from the usual spam or denial of service XMLRPC attacks.
There’s [link moderated – keep support on this site] for anyone interested.
As usual, the best cure for these is a strong password. But this may provide an extra boost to those who feel that xmlrpc.php should be completely disabled.
- The topic ‘Recent new xmlrpc.php brute force password-guessing attack details’ is closed to new replies.