Skip to content

Conversation

@ics
Copy link
Contributor

@ics ics commented Jan 3, 2021

Add IPs observed enumerating and brute forcing fake WordPress installations.

Sample hit:

POST /xmlrpc.php HTTP/1.0 Host: <redacted> X-Real-IP: 37.59.54.36 X-Forwarded-For: 160.105.41.213, 37.59.54.36 Connection: close Content-Length: 190 Accept-Encoding: gzip, deflate Accept: */* User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36 referer: http://www.google.com.hk <?xml version="1.0" encoding="UTF-8"?><methodCall><methodName>wp.getUsersBlogs</methodName><params><param><value></value></param><param><value>@20202020</value></param></params></methodCall>``` 
Copy link
Owner

@mitchellkrogza mitchellkrogza left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The bad ip address list gets updated automatically every day so I cannot merge this as it will get overwritten in 24 hours. I draw the lists daily from badips.com. I can introduce a separate local generator file that can me merged into the daily list every day but good chances many of these will show up in the next update in 2 hours.

@ics ics deleted the wordpress-brutes branch January 3, 2021 13:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants