My girlfriend was just looking at her stats and noticed a referrer she didn't know: /xml-rpc, not really a referrer! The strange thing is that /xml-rpc is also on top of the list with files use by kbyte. She's on 2.6.2 and has xml-rpc publishing disabled.
Is this some kind of hack attempt with an old WP vulnerability? I don't like either note in her stats (referrer?, largest file?).
Any ideas anyone?
It probably is somebody trying to exploit older vulnerabilities. Could also be attempts to send pingback spam.
Ok. I guess Bad Behavior will catch all/most of those. I'll have a look at some server logs to see if I see anything fishy. That'll be tomorrow though. Thanks for your reply.
Hm (couldn't resist). Bad Behavior doesn't block much, 2 access attempts in the last 7 days. Pingbacks are disallowed. No comments in moderation.
So I suppose it'll be just futile automatic attempts.