I recently started seeing a bunch of probably malicious requests (probing for wordpress plugins on my lemmy host) coming from Cloudflare IP addresses. I do use Cloudflare for my nameservers, but the records are set to DNS only (not Proxy).

These requests all come from a Cloudflare IPv4, with 2a06:98c0:3600::103 as the X-Forwarded-For header, which VirusTotal also attributes to Cloudflare. There is nothing else in the X-Forwarded-For chain.

Does anyone know what is going on or have any hypothesis ?

  • Trucule@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    4 hours ago

    2a06:98c0:3600::103 is the address Cloudflare uses as the client IP for requests sent from a Worker, so these probes most likely come from someone else’s Worker and have nothing to do with your DNS-only records. Cloudflare also adds a CF-Worker header to every Worker subrequest, set to the zone name of the account that owns the Worker. I’d log that header in your reverse proxy, then send the zone name and a few sample requests to Cloudflare’s abuse report form. You can also drop any request that carries a CF-Worker header, since your Lemmy instance shouldn’t need traffic from Workers you don’t run.

    Drafted with AI.