Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. WordPress (Developer)
  3. XMLRPC or WP-Login Brute Force Login Attempt

XMLRPC or WP-Login Brute Force Login Attempt

Scheduled Pinned Locked Moved WordPress (Developer)
10 Posts 4 Posters 690 Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P Offline
    P Offline
    p44
    translator
    wrote on last edited by
    #1

    Hello all,

    a few days ago I commented on a post about the increase in the use of CPU resources, not entirely justified.

    Digging a little deeper, I noticed that there are bots that try to access Wordpress's xmlrpc.php, with a frequency of about 3 attempts per second.

    alt text

    alt text

    I would like to ask you in your opinion what is the best strategy to block these repeated login attempts. In this case, blocking IP is not the best solution, because I saw they rotate IP addresses.

    Also, strategy have to be managed centrally (and not on specific Wordpress install) because there are many active Wordpress instances.

    For example, could act on "rate limits", described here, reducing this value "HTTP and HTTPS requests - 5000 requests per second per IP" to 2 request per second per IP?

    Thank's a lot

    jdaviescoatesJ 1 Reply Last reply
    0
    • P p44

      Hello all,

      a few days ago I commented on a post about the increase in the use of CPU resources, not entirely justified.

      Digging a little deeper, I noticed that there are bots that try to access Wordpress's xmlrpc.php, with a frequency of about 3 attempts per second.

      alt text

      alt text

      I would like to ask you in your opinion what is the best strategy to block these repeated login attempts. In this case, blocking IP is not the best solution, because I saw they rotate IP addresses.

      Also, strategy have to be managed centrally (and not on specific Wordpress install) because there are many active Wordpress instances.

      For example, could act on "rate limits", described here, reducing this value "HTTP and HTTPS requests - 5000 requests per second per IP" to 2 request per second per IP?

      Thank's a lot

      jdaviescoatesJ Offline
      jdaviescoatesJ Offline
      jdaviescoates
      wrote on last edited by
      #2

      @p44 said in XMLRPC or WP-Login Brute Force Login Attempt:

      I would like to ask you in your opinion what is the best strategy to block these repeated login attempts.

      Wordfence.

      IMHO every single WordPress site should have Wordfence installed immediately.

      Some interesting reading here

      https://www.wordfence.com/blog/2017/01/xmlrpc-wp-login-brute-force/

      I use Cloudron with Gandi & Hetzner

      P 1 Reply Last reply
      2
      • jdaviescoatesJ jdaviescoates

        @p44 said in XMLRPC or WP-Login Brute Force Login Attempt:

        I would like to ask you in your opinion what is the best strategy to block these repeated login attempts.

        Wordfence.

        IMHO every single WordPress site should have Wordfence installed immediately.

        Some interesting reading here

        https://www.wordfence.com/blog/2017/01/xmlrpc-wp-login-brute-force/

        P Offline
        P Offline
        p44
        translator
        wrote on last edited by
        #3

        @jdaviescoates Thank's a lot for suggestion πŸ™.

        It seems that is not really really cheap...

        What do you think about this: hidemywpghost, suggested by @marcusquinn in this post?

        marcusquinnM imc67I jdaviescoatesJ 3 Replies Last reply
        1
        • P p44

          @jdaviescoates Thank's a lot for suggestion πŸ™.

          It seems that is not really really cheap...

          What do you think about this: hidemywpghost, suggested by @marcusquinn in this post?

          marcusquinnM Offline
          marcusquinnM Offline
          marcusquinn
          wrote on last edited by
          #4

          @p44 Try this for free: https://wordpress.org/plugins/gotmls/

          Web Design https://www.evergreen.je
          Development https://brandlight.org
          Life https://marcusquinn.com

          P 1 Reply Last reply
          1
          • marcusquinnM marcusquinn

            @p44 Try this for free: https://wordpress.org/plugins/gotmls/

            P Offline
            P Offline
            p44
            translator
            wrote on last edited by
            #5

            Thank's a lot @marcusquinn I'll go to look this solution, even if I would like to explore what I can do centrally on Cloudron (Eg. act on "rate limits", or other possible solutions).

            Thank's again πŸ™

            1 Reply Last reply
            0
            • P p44

              @jdaviescoates Thank's a lot for suggestion πŸ™.

              It seems that is not really really cheap...

              What do you think about this: hidemywpghost, suggested by @marcusquinn in this post?

              imc67I Offline
              imc67I Offline
              imc67
              translator
              wrote on last edited by
              #6

              @p44 said in XMLRPC or WP-Login Brute Force Login Attempt:

              @jdaviescoates Thank's a lot for suggestion πŸ™.

              It seems that is not really really cheap...

              The free version of Wordfence is more than enough for most sites, I definitely can recommend Wordfence, it’s always on every website I create.

              P 1 Reply Last reply
              3
              • imc67I imc67

                @p44 said in XMLRPC or WP-Login Brute Force Login Attempt:

                @jdaviescoates Thank's a lot for suggestion πŸ™.

                It seems that is not really really cheap...

                The free version of Wordfence is more than enough for most sites, I definitely can recommend Wordfence, it’s always on every website I create.

                P Offline
                P Offline
                p44
                translator
                wrote on last edited by
                #7

                Thank's a lot @imc67, I'll go deeper in Wordfence.

                Any further suggestion is appreciated

                1 Reply Last reply
                0
                • P p44

                  @jdaviescoates Thank's a lot for suggestion πŸ™.

                  It seems that is not really really cheap...

                  What do you think about this: hidemywpghost, suggested by @marcusquinn in this post?

                  jdaviescoatesJ Offline
                  jdaviescoatesJ Offline
                  jdaviescoates
                  wrote on last edited by
                  #8

                  @p44 said in XMLRPC or WP-Login Brute Force Login Attempt:

                  It seems that is not really really cheap...

                  Um, it's free (well, the free version is - which is perfectly sufficient for most people's need. I've never paid a penny)

                  https://wordpress.org/plugins/wordfence/

                  I use Cloudron with Gandi & Hetzner

                  P 1 Reply Last reply
                  1
                  • jdaviescoatesJ jdaviescoates

                    @p44 said in XMLRPC or WP-Login Brute Force Login Attempt:

                    It seems that is not really really cheap...

                    Um, it's free (well, the free version is - which is perfectly sufficient for most people's need. I've never paid a penny)

                    https://wordpress.org/plugins/wordfence/

                    P Offline
                    P Offline
                    p44
                    translator
                    wrote on last edited by
                    #9

                    @jdaviescoates Thank's. What about CPU usage and memory use of Wordfence?

                    jdaviescoatesJ 1 Reply Last reply
                    0
                    • P p44

                      @jdaviescoates Thank's. What about CPU usage and memory use of Wordfence?

                      jdaviescoatesJ Offline
                      jdaviescoatesJ Offline
                      jdaviescoates
                      wrote on last edited by
                      #10

                      @p44 no idea

                      I use Cloudron with Gandi & Hetzner

                      1 Reply Last reply
                      1
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search