I recently started seeing a bunch of probably malicious requests (probing for wordpress plugins on my lemmy host) coming from Cloudflare IP addresses. I do use Cloudflare for my nameservers, but the records are set to DNS only (not Proxy).

These requests all come from a Cloudflare IPv4, with 2a06:98c0:3600::103 as the X-Forwarded-For header, which VirusTotal also attributes to Cloudflare. There is nothing else in the X-Forwarded-For chain.

Does anyone know what is going on or have any hypothesis ?

  • SteveTech@aussie.zone
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 days ago

    So it seems I was wrong about Cloudflare having seperate prefixes for WAF and workers. And these are all WAF/workers IPs (but not warp). My guess is that someone’s made themselves a http proxy worker, and are using that to proxy their bot’s requests.