Title: brute force attack from multiple locations.
Last modified: September 1, 2016

---

# brute force attack from multiple locations.

 *  [zm11011](https://wordpress.org/support/users/zm11011/)
 * (@zm11011)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/brute-force-attack-from-multiple-locations/)
 * Hi I run the paid Wordfence, Over the last few days I have noticed multiple failed
   login attempts every few minutes and it is through xmlrpc.php
 * and they’re all from different IP addresses, from different locations around 
   the world. so It never get blocked or locked out or throttled as they are all
   from different IPs and locations.
 * I can see they are trying same username for few days and then other same username
   for few days. but they are from different IPs and locations every single time.
 * Can advise any solution?
 * Thanks
 * [https://wordpress.org/plugins/wordfence/](https://wordpress.org/plugins/wordfence/)

Viewing 5 replies - 1 through 5 (of 5 total)

 *  [mountainguy2](https://wordpress.org/support/users/mountainguy2/)
 * (@mountainguy2)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/brute-force-attack-from-multiple-locations/#post-7497271)
 * My solution:
 * 1. Install and enable plugin “Disable XML-RPC”
    2. Rename XML-RPC file in site
   root so it ceases to exist. 3. Add to .htaccess <Files xmlrpc.php> deny from 
   all </Files> 4. Use country blocking whenever possible. 5. Thank the WordPress
   developers for their nice little bot attractant known as xmlrpc.php. It’s so 
   kind of them to give us ways to enjoy watching swarms of bots take down our websites.
 * 6. See [https://wordpress.org/support/topic/xmlrpcphp-attack-on-wordpress-38?replies=28](https://wordpress.org/support/topic/xmlrpcphp-attack-on-wordpress-38?replies=28)
 * MTN
 *  Thread Starter [zm11011](https://wordpress.org/support/users/zm11011/)
 * (@zm11011)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/brute-force-attack-from-multiple-locations/#post-7497277)
 * Hi.
 * Thanks for the answer.
 * but does disabling XML-RPG broke things such as jetpack plugin and other mobile
   APP?
 * is there any other way to solve this?
 *  [webby1973](https://wordpress.org/support/users/webby1973/)
 * (@webby1973)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/brute-force-attack-from-multiple-locations/#post-7497312)
 * I have the same problem with about one hundred different IPs each day, WordFence
   is blocking them with the rules “lock invalid usernames” because they try to 
   login with “test”, but the link they use seems to be poiting to xmlrpc.php .
   
   I’m opening a new thread with more infos.
 *  Thread Starter [zm11011](https://wordpress.org/support/users/zm11011/)
 * (@zm11011)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/brute-force-attack-from-multiple-locations/#post-7497337)
 * Hi.
 * Yes, I could use “lock invalid usernames” but they are not good as real customer
   can make mistake easily.
 * Also even If they got blocked with that they are blocked but it is also being
   logged as well for xmlrpc types of attack.
 * On my websites, most of attacks are using XMLRPC, sometimes it uses same IPs 
   but so many login requests in very short time. some other cases are trying same
   user name but different location which I mentioned above.
 * I think none of security plug-in can block XMLRPC without disabling XMLRPC at
   the moment.
 * This is very hard.
 *  [mountainguy2](https://wordpress.org/support/users/mountainguy2/)
 * (@mountainguy2)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/brute-force-attack-from-multiple-locations/#post-7497357)
 * Just forget anything the needs XMLRPC. It’s like Flash, excellent idea that is
   flawed. If stomping on XMLRPC breaks Jetpack, then Jetpack is bogus. We all need
   to say no to this junk, not spend days defending ourselves against attacks due
   to some ivory tower developer’s idea about what we “need” out here in the real
   world. MTN

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘brute force attack from multiple locations.’ is closed to new replies.

 * ![](https://ps.w.org/wordfence/assets/icon.svg?rev=2070865)
 * [Wordfence Security - Firewall, Malware Scan, and Login Security](https://wordpress.org/plugins/wordfence/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wordfence/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wordfence/)
 * [Active Topics](https://wordpress.org/support/plugin/wordfence/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wordfence/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wordfence/reviews/)

 * 5 replies
 * 3 participants
 * Last reply from: [mountainguy2](https://wordpress.org/support/users/mountainguy2/)
 * Last activity: [10 years, 1 month ago](https://wordpress.org/support/topic/brute-force-attack-from-multiple-locations/#post-7497357)
 * Status: not resolved