WordPress App blocks my IP
-
Hi, I have a wordpress site and I want to write drafts from my phone and if necessary, publish posts, so I downloaded the Android app.
The app allows me to log in, I can see my posts, drafts, the only problem is that as soon as I make a post or update a draft, the provider blocks my IP address.
I can unblock it with a little effort, but this happens after every save. When my IP is in block, I get this message on the site:
It seems that the reason for the ban is the frequent access to xmlrpc.php, which is the most typical sign of a hacking attempt for WordPress sites.
Type of ban, reason: continuous, XMLRPC.The environment:
– PHP: 8.2 (ea-php82)
– WordPress 6.7.1 with Customify theme
– WP and plugins are up to date
– The app is on Android Xiaomi Hyper OSWhat I’ve tried based upon suggestions I’ve found in this theme:
- inactivated all plugins
- changed to basic Twenty twenty-four theme
- Application password
- contacted with my provider.
They don’t want to change their security, but they suggested me this link: Logging WordPress android app makes my website unavailable | www.remarpro.com
The plugin wrote on the link unfortunately doesn’t do anything.
However, I found xmlrpc.php in the file browser on the hosting, so I tried in manual mode.1st try with the solution written on the link:
Based on xmlrpc.php I’ve created a copy called xmlrpc2.php.
I got a little help with whis: “you might want to check if it works correctly after the renaming by typing (https://barangolasok.hu/xmlrpc2.php) into the browser’s address bar, and you should get the same result as you see now when typing https://barangolasok.hu/xmlrpc.php: XML-RPC server accepts POST requests only.”
So in the browser the result is:XML-RPC server accepts POST requests only
.
I sethttps://barangolasok.hu/xmlrpc2.php
in the app, unfortunately the result is still IP ban.
2dn try:
In the xmlrpc2.php file I replaced all xmlrpc.php strings with xmlrpc2.php and updated the file on the server.
In the browser the result is:XML-RPC server accepts POST requests only
.
I sethttps://barangolasok.hu/xmlrpc2.php
in the app, unfortunately the result is still IP ban.3rd try:
While searching, I came across a page where this file can be validated https://xmlrpc.blog/https://barangolasok.hu/xmlrpc.php
→ Congratulations! Your site passed the first check.
You can add the blog within the mobile app using the following URL: https://barangolasok.hu/xmlrpc.phphttps://barangolasok.hu/xmlrpc2.php
→ Congratulations! Your site passed the first check.
You can add the blog within the mobile app using the following URL: https://barangolasok.hu/xmlrpc2.php/xmlrpc.php
This is interesting because it does not write only xmlrpc2.php.
Despite this, I tried all three ways, but unfortunately the result is the same, IP ban.https://barangolasok.hu/xmlrpc.php
https://barangolasok.hu/xmlrpc2.php
https://barangolasok.hu/xmlrpc2.php/xmlrpc.php4th try:
Renamed xmlrpc.php to xmlrpc.old on the server so that only xmlrpc2.php remains, but the page doesn’t work at all.I am a simple user, I don’t know too much about WP.
I welcome any suggestions, thank youThe page I need help with: [log in to see the link]
- You must be logged in to reply to this topic.