this post was submitted on 29 Sep 2026
31 points (97.0% liked)

Selfhosted

62664 readers
372 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

I recently started seeing a bunch of probably malicious requests (probing for wordpress plugins on my lemmy host) coming from Cloudflare IP addresses. I do use Cloudflare for my nameservers, but the records are set to DNS only (not Proxy).

These requests all come from a Cloudflare IPv4, with 2a06:98c0:3600::103 as the X-Forwarded-For header, which VirusTotal also attributes to Cloudflare. There is nothing else in the X-Forwarded-For chain.

Does anyone know what is going on or have any hypothesis ?

you are viewing a single comment's thread
view the rest of the comments
[–] SteveTech@aussie.zone 3 points 4 days ago (1 children)

What's the IPv4? I believe Cloudflare has different prefixes for WAF, warp, and workers.

2a06:98c0:3600::103 is definitely a Cloudflare WAF IP, so my guess is someone using either warp or workers is sending requests and added that IP to X-Forwarded-For as a red herring.

[–] pcouy@lemmy.pierre-couy.fr 2 points 4 days ago (1 children)

I got a bunch of them : 104.23.166.79 , 141.101.76.149 , 108.162.238.148 (this one gave me waild-fedi-reach with an unreachable URL as its user agent, and hit legit paths on my lemmy), 104.23.170.65 , 172.71.182.22 , 104.23.172.96 , 172.71.182.234. It's only 2 hits/day, but this seems weird. What's weird as well is that all it does is keep trying to hit /wp-content/plugins/woocommerce/readme.txt on the same couple of subdomains (except for that one waild-fedi-reach user agent)

[–] SteveTech@aussie.zone 2 points 2 days ago

So it seems I was wrong about Cloudflare having seperate prefixes for WAF and workers. And these are all WAF/workers IPs (but not warp). My guess is that someone's made themselves a http proxy worker, and are using that to proxy their bot's requests.