I recently started seeing a bunch of probably malicious requests (probing for wordpress plugins on my lemmy host) coming from Cloudflare IP addresses. I do use Cloudflare for my nameservers, but the records are set to DNS only (not Proxy).

These requests all come from a Cloudflare IPv4, with 2a06:98c0:3600::103 as the X-Forwarded-For header, which VirusTotal also attributes to Cloudflare. There is nothing else in the X-Forwarded-For chain.

Does anyone know what is going on or have any hypothesis ?

  • SteveTech@aussie.zone
    cake
    link
    fedilink
    English
    arrow-up
    3
    ·
    16 hours ago

    What’s the IPv4? I believe Cloudflare has different prefixes for WAF, warp, and workers.

    2a06:98c0:3600::103 is definitely a Cloudflare WAF IP, so my guess is someone using either warp or workers is sending requests and added that IP to X-Forwarded-For as a red herring.

    • pcouy@lemmy.pierre-couy.frOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      16 hours ago

      I got a bunch of them : 104.23.166.79 , 141.101.76.149 , 108.162.238.148 (this one gave me waild-fedi-reach with an unreachable URL as its user agent, and hit legit paths on my lemmy), 104.23.170.65 , 172.71.182.22 , 104.23.172.96 , 172.71.182.234. It’s only 2 hits/day, but this seems weird. What’s weird as well is that all it does is keep trying to hit /wp-content/plugins/woocommerce/readme.txt on the same couple of subdomains (except for that one waild-fedi-reach user agent)