Share

This was fun, in the way that I learned how to stop this kind of attack by editing my .htaccess. file

But, cleaning up thousands of notification emails wasn’t part of the fun.

Also, if you have a self-hosted wordpress blog, I hope you keep it updated and have the appropriate security plugins installed. Otherwise, this would have been so much worse than cleaning up emails.


79.181.107.173 - - [19/Jul/2014:18:37:17 -0400] "POST /xmlrpc.php HTTP/1.1" 200 1475 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)"
89.237.191.102 - - [19/Jul/2014:18:37:21 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
118.211.224.127 - - [19/Jul/2014:18:37:22 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
68.53.250.22 - - [19/Jul/2014:18:37:23 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
81.71.69.226 - - [19/Jul/2014:18:37:25 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
76.11.57.168 - - [19/Jul/2014:18:37:27 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
109.242.216.230 - - [19/Jul/2014:18:37:25 -0400] "POST /xmlrpc.php HTTP/1.1" 200 1475 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)"
151.224.42.193 - - [19/Jul/2014:18:37:28 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
174.5.145.150 - - [19/Jul/2014:18:37:29 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
189.219.50.79 - - [19/Jul/2014:18:37:30 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
109.49.253.118 - - [19/Jul/2014:18:37:32 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
123.140.12.98 - - [19/Jul/2014:18:37:32 -0400] "POST /xmlrpc.php HTTP/1.1" 200 1475 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)"
111.91.26.196 - - [19/Jul/2014:18:37:37 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
203.81.67.251 - - [19/Jul/2014:18:37:38 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
41.164.22.10 - - [19/Jul/2014:18:37:40 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
61.6.246.157 - - [19/Jul/2014:18:37:41 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
79.97.104.77 - - [19/Jul/2014:18:37:42 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
82.159.74.204 - - [19/Jul/2014:18:37:42 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
201.19.253.166 - - [19/Jul/2014:18:37:45 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
221.100.33.130 - - [19/Jul/2014:18:37:47 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
77.166.83.18 - - [19/Jul/2014:18:37:47 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
174.91.93.230 - - [19/Jul/2014:18:37:49 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
193.126.136.215 - - [19/Jul/2014:18:37:46 -0400] "POST /xmlrpc.php HTTP/1.1" 200 1475 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)"
216.185.38.40 - - [19/Jul/2014:18:37:53 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
78.191.54.232 - - [19/Jul/2014:18:37:54 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
46.76.100.208 - - [19/Jul/2014:18:37:54 -0400] "POST /xmlrpc.php HTTP/1.1" 200 1475 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)"
182.71.140.74 - - [19/Jul/2014:18:38:04 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
23.91.146.246 - - [19/Jul/2014:18:38:04 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
75.151.189.38 - - [19/Jul/2014:18:38:08 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
190.98.42.36 - - [19/Jul/2014:18:38:11 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
112.198.251.200 - - [19/Jul/2014:18:38:11 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
178.21.91.88 - - [19/Jul/2014:18:38:13 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
213.155.245.195 - - [19/Jul/2014:18:38:14 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
39.55.254.72 - - [19/Jul/2014:18:38:14 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
125.167.120.90 - - [19/Jul/2014:18:38:16 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
90.148.20.80 - - [19/Jul/2014:18:38:16 -0400] "POST /xmlrpc.php HTTP/1.1" 200 1475 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)"
183.83.148.156 - - [19/Jul/2014:18:38:17 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
173.179.67.12 - - [19/Jul/2014:18:38:19 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
61.199.80.240 - - [19/Jul/2014:18:38:20 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
200.8.85.58 - - [19/Jul/2014:18:38:22 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"
41.225.238.1 - - [19/Jul/2014:18:38:25 -0400] "POST /xmlrpc.php HTTP/1.1" 406 261 "-" "-"

Barnes & Noble
Tagged with:
 

Comments are closed.