Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- SecRule REQUEST_FILENAME "@streq /xmlrpc.php" "chain,phase:4,id:12345,t:none,block,msg:'Wordpress XML-RPC failed authentication (bf).',logdata:'Number of Authentication Failures: %{ip.xmlrpc_brute}'"
- SecRule REQUEST_METHOD "@streq POST" "chain"
- SecRule RESPONSE_BODY "@contains Incorrect username or password." "chain,setvar:xmlrpc_brute=+1,expirevar:xmlrpc_brute=900"
- SecRule IP:xmlrpc_brute "@gt 2"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement