mitchellkrogza / nginx-ultimate-bad-bot-blocker

Nginx Block Bad Bots, Spam Referrer Blocker, Vulnerability Scanners, User-Agents, Malware, Adware, Ransomware, Malicious Sites, with anti-DDOS, Wordpress Theme Detector Blocking and Fail2Ban Jail for Repeat Offenders
Other
3.81k stars 472 forks source link

Add WordPress brute-forcer IPs #422

Closed ics closed 3 years ago

ics commented 3 years ago

Add IPs observed enumerating and brute forcing fake WordPress installations.

Sample hit:


POST /xmlrpc.php HTTP/1.0
Host: <redacted>
X-Real-IP: 37.59.54.36
X-Forwarded-For: 160.105.41.213, 37.59.54.36
Connection: close
Content-Length: 190
Accept-Encoding: gzip, deflate
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36
referer: http://www.google.com.hk

<?xml version="1.0" encoding="UTF-8"?><methodCall><methodName>wp.getUsersBlogs</methodName><params><param><value></value></param><param><value>@20202020</value></param></params></methodCall>```