{"id":6582601,"date":"2015-09-24T21:36:21","date_gmt":"2015-09-24T21:36:21","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/xmlrpcphp-revert-back-pre-35\/"},"modified":"2016-08-30T18:23:42","modified_gmt":"2016-08-30T18:23:42","slug":"xmlrpcphp-revert-back-pre-35","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/xmlrpcphp-revert-back-pre-35\/","title":{"rendered":"xmlrpc.php revert back pre 3.5"},"content":{"rendered":"<p>Before 3 days i decided to test new security for WP with addon &#8220;WP fail2ban&#8221; so i can take advantage of f2b and prevent bruteforce attacks. I set 2 WP sites on my VPS (fresh install) and once done with everything i notice the huge amount of failed logins as f2b start to ban all those IP&#8217;s. So i went to the next step and use htaccess and try to block the bots to directly hit login page. And here is where all the &#8220;fun&#8221; start.<\/p>\n<p>Even with htaccess blocking login page there was decent amount of bots trying to bruteforce login detals. As i didnt know for the WP changes first thing i suspect that something is wrong with my Apache. So i start to dig into Apache conf files then WP theme and addons until i went back to access log files and made another check. After i spent quite some time comparing the results from f2b and access logs i notice many strange connections directly to xmlrpc.php. At that point everything become more clear, bots were exploiting this file to flood my WP in attempt to bruteforce login details.<\/p>\n<p>So if you are not using some addon to keep track on your login attempts (still not sure if this could work) or you are on VPS\/Dedi where you have better control of log files average user doesnt even know what is going on. I can imagine there is some WP users who used htaccess thinking how they blocked direct access to login page. If not htaccess then there is for sure huge amount of users with installed captcha. All this is for nothing, no impact or change on security at all. In reality this is just an illusion as the bots continue to flood your WP site exploiting xmlrpc.php file what, funny but true, makes the job even faster and easier then classic login page.<\/p>\n<p>Who was thinking in his right mind that enabling this option as default and making it hard to disable was the right choice. This is a joke and WP should go back as it was before 3.5 and leave this or any other similar option for the user to decide to turn it on.<\/p>\n","protected":false},"template":"","class_list":["post-6582601","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/6582601","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/6582601\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=6582601"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}