#XML RPC

Every story tagged XML RPC, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

1 story · open in the command center

  • Security & PrivacyHacker News3m

    288,493 Requests – How I Spotted an XML-RPC Brute Force from a Weird Cache Ratio

    A WordPress site experienced a brute-force attack generating 288,493 requests in 24 hours to XML-RPC endpoints, which was detected not through traditional uptime or CPU monitoring, but through an anomalous drop in cache hit ratio from 70-90% to 0.8%. The attack leveraged XML-RPC's system.multicall feature to test hundreds of credentials per request, bypassing conventional rate limiting while consuming significant server resources. This incident highlights the need for defense-in-depth security strategies combining edge protection (WAF rules) and application-level hardening, as well as monitoring non-traditional metrics like cache performance for early threat detection.

Browse all tags