Publipreneur Polimedia: Jurnal Ilmiah Jurusan Penerbitan Politeknik Negeri Media Kreatif
Vol. 13 No. 2 (2025): Jurnal Ilmiah Publipreneur

BRUTEFORCE ATTACK ANALYSIS VIA XMLRPC.PHP FILE ON WORDPRESS

Nurrachman, Yusuf (Unknown)
R.Sulistiyo Wibowo, S.Sn.,M.Sn (Unknown)
Nofiandri Setyasmara, M.T (Unknown)



Article Info

Publish Date
31 Dec 2025

Abstract

WordPress provides an XML-RPC feature through the xmlrpc.php file for external communication. However, this filter is often exploited as a brute-force attack vulnerability because it supports system.multicall, which allows multiple login attempts in a single request. This study analyzed brute-force attacks against xmlrpc.php through simulations in a local environment using WPscan and a Python script called lokoscannerX_ver1. Testing was conducted using two scenarios: WordPress without security and WordPress with security using the Disable XML-RPC plugin and .htaccess file configuration. The results showed that WordPress without security was easily attacked and overloaded the virtual server on the test environment. Meanwhile, after implementing the Disable XML-RPC plugin, attacks were blocked and prevented, while the .htaccess configuration only blocked execution but still allowed user information to be detected. This study emphasizes the importance of disabling XML-RPC as a basic WordPress security measure.

Copyrights © 2025






Journal Info

Abbrev

JIP

Publisher

Subject

Arts Humanities Economics, Econometrics & Finance Languange, Linguistic, Communication & Media Social Sciences

Description

The journal presents researches in the fields related to the competence of design, printing technology, publishing, and hospitality, including photography, animation, fashion, packaging technology, and other creative industry sectors. The journal also considers the development study of character ...