MEMBLOK file XMLRPC.PHP untuk semua website Wordpress

Introduction/Disclaimer

========================

This document may be modified, reproduced, and distributed free of charge, as

long as the “INTRODUCTION/DISCLAIMER” notice and the original author’s name are

both included.

Created Thu Sep 10 06:00:26 +08 2026 - aka ded1

E-mail: ded1[AT]MyBSD.org.my

*Sebarang komen/idea/pertanyaan dialu-alukan.

 
Ada isu sekarang (sejak zaman kebangkitan BOT AI & automation !) semakin banyak bot hacker probe secara automatik file xmlrpc.php di mana-mana website yang menggunakan acuan CMS Wordpress yang boleh menyebabkan beberapa isu termasuk :
 
 
1. DDoS pada server sendiri
 
2. Brute force attack pada laman web berkenaan
 
3. Server CPU / memory naik terlalu tinggi
 
4. serangan Malware pada website
 
5. Website boleh "dirampas" oleh penyerang
 
6. Server crash / hang
 
 
Cadangan:
 
Blok terus xmlrpc.php di web server anda pada config / firewall WAF / .htaccess / menggunakan plugin Wordpress.
 
Cara paling bagus, blok terus di config NGINX / APACHE.
 
 
Baca dan rujuk di:
 
 
1. https://wpmarmite.com/en/xmlrpc-wordpress/
 
 
2. https://elementor.com/blog/xmlrpc-php-in-wordpress/
 
 
3. https://www.liquidweb.com/blog/why-disable-xmlrpc-php/
 
 
4. https://www.cloudways.com/blog/xmlrpc-wordpress/
 
 
Contoh cara blok di config NGINX:
 
 
location = /xmlrpc.php {
 
    deny all;
    return 301 https://www.mimos.my;
 
}
 
 

PERINGATAN : Sila bertindak sebelum BENCANA tiba !!