my website with xmlrpc
]]>In January 2024, I installed a new website and disabled XML-RPC authentication, as I do for every website I install. During maintenance today, I noticed a large number of brute force attacks on /xmlrpc.php (error 503). I don’t know if this has been the case from the beginning or not. I never experienced this before with the other websites.
In the meantime:
I disabled and reset the XML-RPC authentication by marking the option. I’m still getting brute force attacks on /xmlrpc.php.
I also checked the diagnostics but this seems ok.
Any thoughts? Thank you & regards,
Hilde.
PS. I am on the latest version 7.11.3
]]>I created a WordPress site and installed Wordfence plugin. To install Wordfence, I needed to install Jetpack. Do I still need to keep Jetpack for Wordfence to work ? Since today, I have received lots of alerts from Wordfence about /xmlrpc.php and /admin-ajax.php. I believe Jetpack uses /xmlrpc.php. How can I stop having these attack attempts ?
I thank you in advance.
Sincerely,
]]>our site was victim of a brute force attack (and I believe other attacks). I was told by our provider to disable xmlrpc.php, amongst other suggestions.
I see that WordFence, in “Logic security settings”, has this checkbox called “Disable XML-RPC authentication“.
I just wanted to ask if this does the same as disabling xmlrpc.php in .htaccess, e.g. through a piece of code like:
<Files "xmlrpc.php">
Require all denied
</Files>
Thank you!
]]>This is a file from WordFence:
wp-content\plugins\wordfence\vendor\wordfence\wf-waf\src\lib\xmlrpc.php
I already tried disabling the Wordfence firewall, but it didn’t help.
]]>I have disconnected and reconnected Jetpack from my website. I have looked to see that the xmlrpc.php is in fact in my server’s files. I have looked at my .htaccess file and see no mention of XML-RPC or its filename. I have tried to connect via the Jetpack app on my mobile device and also get an error.
What can I do to fix this problem? tyia
]]>Here is my site info
### wp-core ###
version: 6.1.1
site_language: en_US
user_language: en_US
timezone: America/New_York
permalink: /%postname%/
https_status: true
multisite: false
user_registration: 0
blog_public: 1
default_comment_status: undefined
environment_type: production
user_count: 201
dotorg_communication: true
### wp-paths-sizes ###
wordpress_path: /home/dataforg/public_html
wordpress_size: 1.60 GB (1718596431 bytes)
uploads_path: /home/dataforg/public_html/wp-content/uploads
uploads_size: 29.15 MB (30566597 bytes)
themes_path: /home/dataforg/public_html/wp-content/themes
themes_size: 79.99 MB (83879268 bytes)
plugins_path: /home/dataforg/public_html/wp-content/plugins
plugins_size: 271.06 MB (284225553 bytes)
database_size: 85.39 MB (89538560 bytes)
total_size: 2.06 GB (2206806409 bytes)
### wp-dropins (2) ###
advanced-cache.php: true
maintenance.php: true
### wp-active-theme ###
name: Divi Child Theme (Divi-child)
version: 1.0.0
author: David Knapp
author_website: (undefined)
parent_theme: Divi (Divi)
theme_features: core-block-patterns, block-templates, widgets-block-editor, custom-background, automatic-feed-links, post-thumbnails, menus, title-tag, post-formats, woocommerce, wc-product-gallery-zoom, wc-product-gallery-lightbox, wc-product-gallery-slider, customize-selective-refresh-widgets, wp-block-styles, editor-style, widgets
theme_path: /home/dataforg/public_html/wp-content/themes/Divi-child
auto_update: Disabled
### wp-parent-theme ###
name: Divi (Divi)
version: 4.19.1
author: Elegant Themes
author_website: https://www.elegantthemes.com
theme_path: /home/dataforg/public_html/wp-content/themes/Divi
auto_update: Disabled
### wp-themes-inactive (13) ###
Twenty Eleven: version: 4.2, author: the WordPress team, Auto-updates disabled
Twenty Fifteen: version: 3.3, author: the WordPress team, Auto-updates disabled
Twenty Fourteen: version: 3.5, author: the WordPress team, Auto-updates disabled
Twenty Nineteen: version: 2.4, author: the WordPress team, Auto-updates disabled
Twenty Seventeen: version: 3.1, author: the WordPress team, Auto-updates disabled
Twenty Sixteen: version: 2.8, author: the WordPress team, Auto-updates disabled
Twenty Ten: version: 3.7, author: the WordPress team, Auto-updates disabled
Twenty Thirteen: version: 3.7, author: the WordPress team, Auto-updates disabled
Twenty Twelve: version: 3.8, author: the WordPress team, Auto-updates disabled
Twenty Twenty: version: 2.1, author: the WordPress team, Auto-updates disabled
Twenty Twenty-One: version: 1.7, author: the WordPress team, Auto-updates disabled
Twenty Twenty-Three: version: 1.0, author: the WordPress team, Auto-updates disabled
Twenty Twenty-Two: version: 1.3, author: the WordPress team, Auto-updates disabled
### wp-mu-plugins (1) ###
ET Support Center :: Must-Use Plugins Autoloader: author: Elegant Themes, version: (undefined)
### wp-plugins-active (1) ###
Jetpack: version: 11.5.1, author: Automattic, Auto-updates enabled
### wp-plugins-inactive (31) ###
All-in-One WP Migration: version: 7.68, author: ServMask, Auto-updates enabled
Cloudflare: version: 4.11.0, author: Cloudflare, Inc., Auto-updates enabled
Code Snippets Pro: version: 3.2.1, author: Code Snippets Pro, Auto-updates enabled
Divi-Modules – Simple Heading: version: 2.1.2, author: Divi-Modules, Auto-updates enabled
Divi Gallery Extended: version: 1.2.6, author: Elicus, Auto-updates enabled
Duplicate Page: version: 4.4.9, author: mndpsingh287, Auto-updates disabled
EWWW Image Optimizer: version: 6.9.2, author: Exactly WWW, Auto-updates enabled
Facebook for WooCommerce: version: 3.0.3, author: Facebook, Auto-updates enabled
Facebook for WooCommerce - settings tools: version: 1.0.0, author: SkyVerge, Auto-updates enabled
Fluent Forms: version: 4.3.22, author: Contact Form - WPManageNinja LLC, Auto-updates enabled
Google Listings and Ads: version: 2.2.1, author: WooCommerce, Auto-updates enabled
InfiniteWP - Client: version: 1.9.9, author: Revmakx, Auto-updates enabled
Justified Gallery: version: 1.6.0, author: Mateusz Czardybon, Auto-updates enabled
Menu Duplicator: version: 0.6, author: Jeremy Ross, Auto-updates disabled
Payment Gateway Based Fees and Discounts for WooCommerce: version: 2.8.0, author: Tyche Softwares, Auto-updates enabled
Print Invoice & Delivery Notes for WooCommerce: version: 4.6.5, author: Tyche Softwares, Auto-updates enabled
Product Customer List for WooCommerce: version: 3.1.2, author: Kokomo, Auto-updates enabled
REST API Log: version: 1.6.9, author: Pete Nelson, Auto-updates enabled
Site Kit by Google: version: 1.87.0, author: Google, Auto-updates enabled
Supreme Modules Lite - Divi Theme, Extra Theme and Divi Builder: version: 2.4.2, author: Supreme Modules, Auto-updates enabled
UpdraftPlus - Backup/Restore: version: 2.22.23.0, author: UpdraftPlus.Com, DavidAnderson, Auto-updates enabled
VBOUT Woocommerce Plugin: version: 3.6.0, author: VBOUT Inc., Auto-updates disabled
VBOUT WordPress Plugin: version: 1.2.6.6, author: VBOUT Inc., Auto-updates enabled
WooCommerce: version: 7.1.0, author: Automattic, Auto-updates enabled
Woocommerce delete product images: version: 1.0.2, author: Husain Ahmed, Auto-updates enabled
Woocommerce QuickBooks Connector: version: 2.2.9, author: Techspawn Solutions, Auto-updates enabled
WooCommerce Shipping & Tax: version: 2.0.0, author: WooCommerce, Auto-updates enabled
WooCommerce Stripe Gateway: version: 7.0.1, author: WooCommerce, Auto-updates enabled
WooCommerce Visibility: version: 5.2, author: codemine, Auto-updates enabled
Wordfence Security: version: 7.7.1, author: Wordfence, Auto-updates enabled
WP Offload Media Lite: version: 3.0.2, author: Delicious Brains, Auto-updates enabled
### wp-media ###
image_editor: WP_Image_Editor_Imagick
imagick_module_version: 1690
imagemagick_version: ImageMagick 6.9.10-68 Q16 x86_64 2021-10-14 https://imagemagick.org
imagick_version: 3.7.0
file_uploads: File uploads is turned off
post_max_size: 16M
upload_max_filesize: 16M
max_effective_size: 16 MB
max_file_uploads: 20
imagick_limits:
imagick::RESOURCETYPE_AREA: 58 GB
imagick::RESOURCETYPE_DISK: 9.2233720368548E+18
imagick::RESOURCETYPE_FILE: 12288
imagick::RESOURCETYPE_MAP: 58 GB
imagick::RESOURCETYPE_MEMORY: 29 GB
imagick::RESOURCETYPE_THREAD: 1
imagemagick_file_formats: 3FR, 3G2, 3GP, AAI, AI, ART, ARW, AVI, AVS, BGR, BGRA, BGRO, BMP, BMP2, BMP3, BRF, CAL, CALS, CANVAS, CAPTION, CIN, CIP, CLIP, CMYK, CMYKA, CR2, CRW, CUR, CUT, DATA, DCM, DCR, DCX, DDS, DFONT, DNG, DOT, DPX, DXT1, DXT5, EPDF, EPI, EPS, EPS2, EPS3, EPSF, EPSI, EPT, EPT2, EPT3, ERF, EXR, FAX, FILE, FITS, FRACTAL, FTP, FTS, G3, G4, GIF, GIF87, GRADIENT, GRAY, GRAYA, GROUP4, GV, H, HALD, HDR, HISTOGRAM, HRZ, HTM, HTML, HTTP, HTTPS, ICB, ICO, ICON, IIQ, INFO, INLINE, IPL, ISOBRL, ISOBRL6, J2C, J2K, JNG, JNX, JP2, JPC, JPE, JPEG, JPG, JPM, JPS, JPT, JSON, K25, KDC, LABEL, M2V, M4V, MAC, MAGICK, MAP, MASK, MAT, MATTE, MEF, MIFF, MKV, MNG, MONO, MOV, MP4, MPC, MPEG, MPG, MRW, MSL, MSVG, MTV, MVG, NEF, NRW, NULL, ORF, OTB, OTF, PAL, PALM, PAM, PANGO, PATTERN, PBM, PCD, PCDS, PCL, PCT, PCX, PDB, PDF, PDFA, PEF, PES, PFA, PFB, PFM, PGM, PGX, PICON, PICT, PIX, PJPEG, PLASMA, PNG, PNG00, PNG24, PNG32, PNG48, PNG64, PNG8, PNM, PPM, PREVIEW, PS, PS2, PS3, PSB, PSD, PTIF, PWP, RADIAL-GRADIENT, RAF, RAS, RAW, RGB, RGBA, RGBO, RGF, RLA, RLE, RMF, RW2, SCR, SCT, SFW, SGI, SHTML, SIX, SIXEL, SPARSE-COLOR, SR2, SRF, STEGANO, SUN, SVG, SVGZ, TEXT, TGA, THUMBNAIL, TIFF, TIFF64, TILE, TIM, TTC, TTF, TXT, UBRL, UBRL6, UIL, UYVY, VDA, VICAR, VID, VIFF, VIPS, VST, WBMP, WMF, WMV, WMZ, WPG, X, X3F, XBM, XC, XCF, XPM, XPS, XV, XWD, YCbCr, YCbCrA, YUV
gd_version: bundled (2.1.0 compatible)
gd_formats: GIF, JPEG, PNG, WebP, BMP, XPM
ghostscript_version: 9.25
### wp-server ###
server_architecture: Linux 3.10.0-962.3.2.lve1.5.49.el7.x86_64 x86_64
httpd_software: Apache
php_version: 7.4.33 64bit
php_sapi: cgi-fcgi
max_input_variables: 1000
time_limit: 300
memory_limit: 128M
admin_memory_limit: 256M
max_input_time: 60
upload_max_filesize: 16M
php_post_max_size: 16M
curl_version: 7.86.0 OpenSSL/1.1.1s
suhosin: false
imagick_availability: true
pretty_permalinks: true
htaccess_extra_rules: true
### wp-database ###
extension: mysqli
server_version: 5.7.40
client_version: mysqlnd 7.4.33
max_allowed_packet: 268435456
max_connections: 500
### wp-constants ###
WP_HOME: undefined
WP_SITEURL: undefined
WP_CONTENT_DIR: /home/dataforg/public_html/wp-content
WP_PLUGIN_DIR: /home/dataforg/public_html/wp-content/plugins
WP_MEMORY_LIMIT: 40M
WP_MAX_MEMORY_LIMIT: 256M
WP_DEBUG: false
WP_DEBUG_DISPLAY: true
WP_DEBUG_LOG: false
SCRIPT_DEBUG: false
WP_CACHE: false
CONCATENATE_SCRIPTS: undefined
COMPRESS_SCRIPTS: undefined
COMPRESS_CSS: undefined
WP_ENVIRONMENT_TYPE: Undefined
DB_CHARSET: utf8mb4
DB_COLLATE: undefined
### wp-filesystem ###
wordpress: writable
wp-content: writable
uploads: writable
plugins: writable
themes: writable
mu-plugins: writable
### jetpack ###
site_id: false
ssl_cert: No
time_diff: -1
version_option: 11.5.1:1668876034
old_version: 11.5.1:1668876034
public: Private
master_user: No master user set.
current_user: #1 dataforge
tokens_set: None
blog_token: Not set.
user_token: Not set.
version: 11.5.1
jp_plugin_dir: /home/dataforg/public_html/wp-content/plugins/jetpack/
plan: free
protect_header: {"trusted_header":"REMOTE_ADDR","segments":1,"reverse":false}
full_sync: {"started":"Thu, 01 Jan 1970 00:00:00 +0000","finished":"Thu, 01 Jan 1970 00:00:00 +0000","progress":[],"config":[]}
sync_size: undefined
sync_lag: 0 seconds
full_sync_size: undefined
full_sync_lag: 0 seconds
idc_urls: {"home":"https:\/\/dataforge.us","siteurl":"https:\/\/dataforge.us","WP_HOME":"","WP_SITEURL":""}
idc_error_option: false
idc_optin: true
cxn_tests: All Pass.
]]>