I recently started seeing a bunch of probably malicious requests (probing for wordpress plugins on my lemmy host) coming from Cloudflare IP addresses. I do use Cloudflare for my nameservers, but the records are set to DNS only (not Proxy).
These requests all come from a Cloudflare IPv4, with 2a06:98c0:3600::103 as the X-Forwarded-For header, which VirusTotal also attributes to Cloudflare. There is nothing else in the X-Forwarded-For chain.
Does anyone know what is going on or have any hypothesis ?
2a06:98c0:3600::103 is the address Cloudflare uses as the client IP for requests sent from a Worker, so these probes most likely come from someone else’s Worker and have nothing to do with your DNS-only records. Cloudflare also adds a CF-Worker header to every Worker subrequest, set to the zone name of the account that owns the Worker. I’d log that header in your reverse proxy, then send the zone name and a few sample requests to Cloudflare’s abuse report form. You can also drop any request that carries a CF-Worker header, since your Lemmy instance shouldn’t need traffic from Workers you don’t run.
Drafted with AI.
What’s the IPv4? I believe Cloudflare has different prefixes for WAF, warp, and workers.
2a06:98c0:3600::103is definitely a Cloudflare WAF IP, so my guess is someone using either warp or workers is sending requests and added that IP toX-Forwarded-Foras a red herring.I got a bunch of them : 104.23.166.79 , 141.101.76.149 , 108.162.238.148 (this one gave me
waild-fedi-reachwith an unreachable URL as its user agent, and hit legit paths on my lemmy), 104.23.170.65 , 172.71.182.22 , 104.23.172.96 , 172.71.182.234. It’s only 2 hits/day, but this seems weird. What’s weird as well is that all it does is keep trying to hit/wp-content/plugins/woocommerce/readme.txton the same couple of subdomains (except for that one waild-fedi-reach user agent)
Cloudflare have “workers” that can run code, and anyone can create them, my guess is abuse? You can try contacting cloudflare.
Mm I also got probes for WordPress a month or so ago, but after I switched from Cloudflare to Mythic Beasts. Have you switched off the setting that says Cloudflare will allow known AI bots to trawl your domains?

