Title: Warning: XMLRPC WordPress Exploit DDOS
Last modified: August 21, 2016

---

# Warning: XMLRPC WordPress Exploit DDOS

 *  [3Lancer](https://wordpress.org/support/users/3lancer/)
 * (@3lancer)
 * [11 years, 10 months ago](https://wordpress.org/support/topic/warning-xmlrpc-wordpress-exploit-ddos/)
 * WordPress Insecure Default Option = Very Large Botnet of DDOS/Infections. More
   Than 162,000 affected so far.
 * For those unaware, there’s appears to be a XMLRPC exploit going around at the
   moment, which uses the WordPress ‘Post PingBack’ feature to bounce calls from
   site to site, in turn if your site isn’t protected it could be possibly used 
   to in DDOSing other sites.
 * DDOS = Denial-of-service attack, meant to full up and overload requests to your
   server, until real traffic ends up getting blocked or the server crashes.
 * iThemes Security offers blocking of XMLRPC, which I highly recommend using for
   at least the Pingback block, if not completely.
 * The exploit uses ‘libwww-perl’ User Agent, so if you don’t use that it could 
   also be blocked. Note, this plugin use to have that on the default block list,
   but appears it doesn’t anymore by default?
 * Any WordPress site with Pingback enabled (which is on by default) can be used
   in DDOS attacks against other sites. Note that XMLRPC is used for pingbacks, 
   trackbacks, remote access via mobile devices and many other features. So you 
   might be using it for a good purpose.
 * Check your log files for repeats of (possibly every 15 seconds):
    “GET /xmlrpc.
   php HTTP/1.1” “libwww-perl/6.05”
 * If someone else is affected and bombing your site, attempting to infect and/or
   DDOS you! I’m personally unaffected, but getting annoyed by the block logs, so
   advice people to check their own sites and perhaps enable a little more security
   options with this great plugin (XMLRPC and/or libwww-perl disabled or limited).
 * You can also check your website against some already known:
    [http://labs.sucuri.net/?is-my-wordpress-ddosing](http://labs.sucuri.net/?is-my-wordpress-ddosing)
 * [https://wordpress.org/plugins/better-wp-security/](https://wordpress.org/plugins/better-wp-security/)

Viewing 1 replies (of 1 total)

 *  Thread Starter [3Lancer](https://wordpress.org/support/users/3lancer/)
 * (@3lancer)
 * [11 years, 10 months ago](https://wordpress.org/support/topic/warning-xmlrpc-wordpress-exploit-ddos/#post-5165929)
 * Updating your WordPress to the latest 3.9.2 might also help address this issue:
   [http://wordpress.org/news/2014/08/wordpress-3-9-2/](http://wordpress.org/news/2014/08/wordpress-3-9-2/)

Viewing 1 replies (of 1 total)

The topic ‘Warning: XMLRPC WordPress Exploit DDOS’ is closed to new replies.

 * ![](https://ps.w.org/better-wp-security/assets/icon.svg?rev=3529351)
 * [Kadence Security – Password, Two Factor Authentication, and Brute Force Protection](https://wordpress.org/plugins/better-wp-security/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/better-wp-security/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/better-wp-security/)
 * [Active Topics](https://wordpress.org/support/plugin/better-wp-security/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/better-wp-security/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/better-wp-security/reviews/)

## Tags

 * [ddos](https://wordpress.org/support/topic-tag/ddos/)
 * [exploit](https://wordpress.org/support/topic-tag/exploit/)
 * [xmlrpc](https://wordpress.org/support/topic-tag/xmlrpc/)

 * 1 reply
 * 1 participant
 * Last reply from: [3Lancer](https://wordpress.org/support/users/3lancer/)
 * Last activity: [11 years, 10 months ago](https://wordpress.org/support/topic/warning-xmlrpc-wordpress-exploit-ddos/#post-5165929)
 * Status: not resolved