Changes between Initial Version and Version 1 of Ticket #21509, comment 18
- Timestamp:
- 10/26/2014 07:46:18 PM (12 years ago)
Legend:
- Unmodified
- Added
- Removed
- Modified
-
Ticket #21509, comment 18
initial v1 3 3 http://www.computerweekly.com/news/2240215998/More-the-162000-WordPress-sites-used-in-DDoS-attack 4 4 5 Enabling xml-rpc by default has drastically affected the volume of DDOS abuse through xml-rpc onwp sites. I understand it is relatively widely used, however, most wp sites (I believe) do not use pingbacks or wp mobile app by default. I believe it should be reverted back to disabled by default and have plugins and remote services that rely on this to enable it either automagically upon install or in their installation instructions.5 Enabling xml-rpc by default has drastically affected the volume of DDOS abuse through xml-rpc through wp sites. I understand it is relatively widely used, however, most wp sites (I believe) do not use pingbacks or wp mobile app by default. I believe it should be reverted back to disabled by default and have plugins and remote services that rely on this to enable it either automagically upon install or in their installation instructions. 6 6 7 7 I personally found 1 site I manage that has been abused through xml-rpc.php.
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)