I recently started seeing a bunch of probably malicious requests (probing for wordpress plugins on my lemmy host) coming from Cloudflare IP addresses. I do use Cloudflare for my nameservers, but the records are set to DNS only (not Proxy).

These requests all come from a Cloudflare IPv4, with 2a06:98c0:3600::103 as the X-Forwarded-For header, which VirusTotal also attributes to Cloudflare. There is nothing else in the X-Forwarded-For chain.

Does anyone know what is going on or have any hypothesis ?

  • Trucule@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    3 hours ago

    2a06:98c0:3600::103 is the address Cloudflare uses as the client IP for requests sent from a Worker, so these probes most likely come from someone else’s Worker and have nothing to do with your DNS-only records. Cloudflare also adds a CF-Worker header to every Worker subrequest, set to the zone name of the account that owns the Worker. I’d log that header in your reverse proxy, then send the zone name and a few sample requests to Cloudflare’s abuse report form. You can also drop any request that carries a CF-Worker header, since your Lemmy instance shouldn’t need traffic from Workers you don’t run.

    Drafted with AI.

  • SteveTech@aussie.zone
    link
    fedilink
    English
    arrow-up
    3
    ·
    9 hours ago

    What’s the IPv4? I believe Cloudflare has different prefixes for WAF, warp, and workers.

    2a06:98c0:3600::103 is definitely a Cloudflare WAF IP, so my guess is someone using either warp or workers is sending requests and added that IP to X-Forwarded-For as a red herring.

    • pcouy@lemmy.pierre-couy.frOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      8 hours ago

      I got a bunch of them : 104.23.166.79 , 141.101.76.149 , 108.162.238.148 (this one gave me waild-fedi-reach with an unreachable URL as its user agent, and hit legit paths on my lemmy), 104.23.170.65 , 172.71.182.22 , 104.23.172.96 , 172.71.182.234. It’s only 2 hits/day, but this seems weird. What’s weird as well is that all it does is keep trying to hit /wp-content/plugins/woocommerce/readme.txt on the same couple of subdomains (except for that one waild-fedi-reach user agent)

  • gole@lemmy.zip
    link
    fedilink
    English
    arrow-up
    23
    ·
    14 hours ago

    Cloudflare have “workers” that can run code, and anyone can create them, my guess is abuse? You can try contacting cloudflare.

  • lyralycan@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    7
    ·
    14 hours ago

    Mm I also got probes for WordPress a month or so ago, but after I switched from Cloudflare to Mythic Beasts. Have you switched off the setting that says Cloudflare will allow known AI bots to trawl your domains?