I recently started seeing a bunch of probably malicious requests (probing for wordpress plugins on my lemmy host) coming from Cloudflare IP addresses. I do use Cloudflare for my nameservers, but the records are set to DNS only (not Proxy).
These requests all come from a Cloudflare IPv4, with 2a06:98c0:3600::103 as the X-Forwarded-For header, which VirusTotal also attributes to Cloudflare. There is nothing else in the X-Forwarded-For chain.
Does anyone know what is going on or have any hypothesis ?
Since your records are DNS-only, these requests hit your origin directly, so you can deal with them there no matter who is behind the Worker. A Lemmy host has no WordPress, so anything asking for /wp-login.php, /wp-content/ or /xmlrpc.php is junk. Two cheap fixes: have your reverse proxy reject those paths outright, or use CrowdSec with its WordPress/http-probing scenarios, which bans the source after a few hits.
Adding to the Workers theory: if it is a Worker, Cloudflare adds a
CF-Workerrequest header to every subrequest a Worker makes, and its value is the zone the Worker belongs to (e.g.something.workers.devor the owner’s own domain). It’s not something the script can strip, so if you add that header to your reverse proxy’s log format you should be able to see exactly whose Worker is probing you.That gives you two practical options: report it through Cloudflare’s abuse form with the zone name (they do act on Workers being used for scanning), and/or drop any request that carries a
CF-Workerheader at the proxy, since nothing legitimate should be hitting a DNS-only Lemmy host through a Worker anyway. Federation traffic from other instances won’t have it.People abusing cloudflare workers.
Cloudflare have “workers” that can run code, and anyone can create them, my guess is abuse? You can try contacting cloudflare.
Mm I also got probes for WordPress a month or so ago, but after I switched from Cloudflare to Mythic Beasts. Have you switched off the setting that says Cloudflare will allow known AI bots to trawl your domains?
What’s the IPv4? I believe Cloudflare has different prefixes for WAF, warp, and workers.
2a06:98c0:3600::103is definitely a Cloudflare WAF IP, so my guess is someone using either warp or workers is sending requests and added that IP toX-Forwarded-Foras a red herring.I got a bunch of them : 104.23.166.79 , 141.101.76.149 , 108.162.238.148 (this one gave me
waild-fedi-reachwith an unreachable URL as its user agent, and hit legit paths on my lemmy), 104.23.170.65 , 172.71.182.22 , 104.23.172.96 , 172.71.182.234. It’s only 2 hits/day, but this seems weird. What’s weird as well is that all it does is keep trying to hit/wp-content/plugins/woocommerce/readme.txton the same couple of subdomains (except for that one waild-fedi-reach user agent)So it seems I was wrong about Cloudflare having seperate prefixes for WAF and workers. And these are all WAF/workers IPs (but not warp). My guess is that someone’s made themselves a http proxy worker, and are using that to proxy their bot’s requests.
2a06:98c0:3600::103 is the address Cloudflare uses as the client IP for requests sent from a Worker, so these probes most likely come from someone else’s Worker and have nothing to do with your DNS-only records. Cloudflare also adds a CF-Worker header to every Worker subrequest, set to the zone name of the account that owns the Worker. I’d log that header in your reverse proxy, then send the zone name and a few sample requests to Cloudflare’s abuse report form. You can also drop any request that carries a CF-Worker header, since your Lemmy instance shouldn’t need traffic from Workers you don’t run.
Drafted with AI.



