{"id":232508,"date":"2023-01-22T18:47:00","date_gmt":"2023-01-22T15:47:00","guid":{"rendered":"https:\/\/wordpress.mediadoma.com\/?p=232508"},"modified":"2022-11-10T10:07:45","modified_gmt":"2022-11-10T07:07:45","slug":"quickhostuk-wordpress-attaques-damplification-par-force-brute-contre-xmlrpc","status":"publish","type":"post","link":"https:\/\/wordpress.mediadoma.com\/fr\/quickhostuk-wordpress-attaques-damplification-par-force-brute-contre-xmlrpc\/","title":{"rendered":"QuickhostUK &#8211; WordPress &#8211; Attaques d&rsquo;amplification par force brute contre XMLRPC"},"content":{"rendered":"<p>Selon l&rsquo;avis de s\u00e9curit\u00e9 de Sucuri &#8211;<\/p>\n<p>quickhostuk<\/p>\n<blockquote>\n<p>Les attaquants exploitent l&rsquo;une des fonctionnalit\u00e9s cach\u00e9es de XML-RPC &#8211; en utilisant la m\u00e9thode system.multicall pour ex\u00e9cuter plusieurs tentatives Brute Force dans une seule demande de publication. Au lieu de cibler directement wp-login.php, l&rsquo;utilisateur contourne le syst\u00e8me en ciblant des m\u00e9thodes dans le tr\u00e8s populaire XML-RPC.<\/p>\n<\/blockquote>\n<p>Cette attaque amplifie les tentatives de Brute Force dans des ordres de grandeur tr\u00e8s \u00e9lev\u00e9s et d\u00e9guise les tentatives dans une technique qui la rend tr\u00e8s difficile \u00e0 identifier et \u00e0 att\u00e9nuer. En tirant parti de la m\u00e9thode system.multicall dans <a href=\"https:\/\/helloacm.com\/using-xmlhttp-in-vbscript\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">XML-RPC,<\/a> l&rsquo;attaquant est capable de masquer des centaines\/milliers de mots de passe dans une seule requ\u00eate HTTP\/ <a href=\"https:\/\/helloacm.com\/how-to-setup-multiple-ssl-https-on-one-server-vps-or-dedicate-server\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">HTTPS<\/a>.<\/p>\n<p>Si vous \u00eates un client QuickHostUK Managed Hosting, vous \u00eates d\u00e9j\u00e0 prot\u00e9g\u00e9 contre cela.<\/p>\n<p>Si vous n&rsquo;\u00eates pas un <a href=\"https:\/\/helloacm.com\/quickhostuk-vps-upgrade-to-ssd\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">client QuickHostUK<\/a> Managed Hosting, veuillez vous assurer que vous avez \u00e9galement pris les mesures appropri\u00e9es pour s\u00e9curiser votre ou vos propres sites. Il est conseill\u00e9 de bloquer XML-RPC via vos fichiers .htaccess ou d&rsquo;utiliser une m\u00e9thode pour d\u00e9pouiller les requ\u00eates ciblant le system.multicall. Alternativement, nous pouvons g\u00e9rer cela pour vous avec notre syst\u00e8me de gestion ad hoc, qui pour cet \u00e9v\u00e9nement serait de 10 \u00a3 TTC par site.<\/p>\n<p>Veuillez nous contacter si vous souhaitez utiliser ce service ou si vous avez des questions.<\/p>\n<p>Sinc\u00e8res amiti\u00e9s,<\/p>\n<p>QuickHostUK Limited<\/p>\n<p>Note: 0.0\/ <strong>10<\/strong> (0 suffrages exprim\u00e9s)<\/p>\n<p>302 mots<br \/>\n<strong>Last Post<\/strong>: <a href=\"https:\/\/helloacm.com\/why-c-another-case-study\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">pourquoi C++ \u2013 une autre \u00e9tude de cas ?<\/a><br \/>\n<strong>Article suivant<\/strong>: <a href=\"https:\/\/helloacm.com\/delphi-tparallel-cleanup-needed\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Delphi TParallel Cleanup N\u00e9cessaire<\/a><\/p>\n<p><div id=\"PostUnique_PostSource\" style=\"padding-top: 50px\">Source d&rsquo;enregistrement:  <a target=\"_blank\" rel=\"noopener nofollow\" href=\"\/\/helloacm.com\" class=\"external external_icon\">helloacm.com<\/a><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>QuickhostUK &#8211; WordPress &#8211; Attaques d&rsquo;amplification par force brute contre XMLRPC<\/p>\n","protected":false},"author":1,"featured_media":223608,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wp_rev_ctl_limit":""},"categories":[717,1028,841,862],"tags":[1167],"class_list":["post-232508","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-developpeur","category-securite","category-tutoriels","category-wordpress-3","tag-affiai-fr"],"_links":{"self":[{"href":"https:\/\/wordpress.mediadoma.com\/fr\/wp-json\/wp\/v2\/posts\/232508","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.mediadoma.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wordpress.mediadoma.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.mediadoma.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.mediadoma.com\/fr\/wp-json\/wp\/v2\/comments?post=232508"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.mediadoma.com\/fr\/wp-json\/wp\/v2\/posts\/232508\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.mediadoma.com\/fr\/wp-json\/wp\/v2\/media?parent=232508"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wordpress.mediadoma.com\/fr\/wp-json\/wp\/v2\/categories?post=232508"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wordpress.mediadoma.com\/fr\/wp-json\/wp\/v2\/tags?post=232508"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}