We are often asked how to block the DFind vulnerability scanner (A.K.A. "w00tw00t.at.ISC.SANS.DFind") with NinjaFirewall, our Web Application Firewall for PHP and WordPress.
The bad news is that you can't. But the good news is that you don't have to, because it is already blocked!
Several years ago, I wrote an article about it, so let's see that issue again.
If you have one ore more servers, there are a lot of chances that you saw the "w00tw00t" connection attempts inside your Apache logs: