Overview
XML-RPC lets one HTTP request carry hundreds of system.multicall auth attempts, so a single connection becomes a password-spraying amplifier that defeats simple rate limiting.\nThe pingback.ping method also makes the server issue outbound requests, which fuels DDoS reflection and internal port scanning.\nMost sites do not need it: disable the endpoint unless a legacy integration genuinely depends on it.
Indicators of Compromise
Signals that suggest this is present on a system.
- POST /xmlrpc.php returning a methods list
- system.multicall accepted
- Unsolicited pingback notifications
Controls that stop it
-
Patch Promptly and Continuously
Maintain an inventory of every framework, plugin and library you run, subscribe to their advisories, and apply fixes on a defined SLA measured in days rather than months. Prioritise anything reachable from the internet or already exploited in the wild. Automate the process so patching does not depend on someone remembering to do it.