this post was submitted on 29 Sep 2026
31 points (97.0% liked)

Selfhosted

62664 readers
372 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

I recently started seeing a bunch of probably malicious requests (probing for wordpress plugins on my lemmy host) coming from Cloudflare IP addresses. I do use Cloudflare for my nameservers, but the records are set to DNS only (not Proxy).

These requests all come from a Cloudflare IPv4, with 2a06:98c0:3600::103 as the X-Forwarded-For header, which VirusTotal also attributes to Cloudflare. There is nothing else in the X-Forwarded-For chain.

Does anyone know what is going on or have any hypothesis ?

top 9 comments
sorted by: hot top controversial new old
[–] london443@lemmy.world 1 points 1 day ago

Since your records are DNS-only, these requests hit your origin directly, so you can deal with them there no matter who is behind the Worker. A Lemmy host has no WordPress, so anything asking for /wp-login.php, /wp-content/ or /xmlrpc.php is junk. Two cheap fixes: have your reverse proxy reject those paths outright, or use CrowdSec with its WordPress/http-probing scenarios, which bans the source after a few hits.

[–] ahmedezat_katteb@lemmy.world 2 points 2 days ago

Adding to the Workers theory: if it is a Worker, Cloudflare adds a CF-Worker request header to every subrequest a Worker makes, and its value is the zone the Worker belongs to (e.g. something.workers.dev or the owner's own domain). It's not something the script can strip, so if you add that header to your reverse proxy's log format you should be able to see exactly whose Worker is probing you.

That gives you two practical options: report it through Cloudflare's abuse form with the zone name (they do act on Workers being used for scanning), and/or drop any request that carries a CF-Worker header at the proxy, since nothing legitimate should be hitting a DNS-only Lemmy host through a Worker anyway. Federation traffic from other instances won't have it.

[–] gole@lemmy.zip 26 points 5 days ago

Cloudflare have "workers" that can run code, and anyone can create them, my guess is abuse? You can try contacting cloudflare.

People abusing cloudflare workers.

[–] lyralycan@sh.itjust.works 7 points 5 days ago

Mm I also got probes for WordPress a month or so ago, but after I switched from Cloudflare to Mythic Beasts. Have you switched off the setting that says Cloudflare will allow known AI bots to trawl your domains?

[–] SteveTech@aussie.zone 3 points 4 days ago (1 children)

What's the IPv4? I believe Cloudflare has different prefixes for WAF, warp, and workers.

2a06:98c0:3600::103 is definitely a Cloudflare WAF IP, so my guess is someone using either warp or workers is sending requests and added that IP to X-Forwarded-For as a red herring.

[–] pcouy@lemmy.pierre-couy.fr 2 points 4 days ago (1 children)

I got a bunch of them : 104.23.166.79 , 141.101.76.149 , 108.162.238.148 (this one gave me waild-fedi-reach with an unreachable URL as its user agent, and hit legit paths on my lemmy), 104.23.170.65 , 172.71.182.22 , 104.23.172.96 , 172.71.182.234. It's only 2 hits/day, but this seems weird. What's weird as well is that all it does is keep trying to hit /wp-content/plugins/woocommerce/readme.txt on the same couple of subdomains (except for that one waild-fedi-reach user agent)

[–] SteveTech@aussie.zone 2 points 2 days ago

So it seems I was wrong about Cloudflare having seperate prefixes for WAF and workers. And these are all WAF/workers IPs (but not warp). My guess is that someone's made themselves a http proxy worker, and are using that to proxy their bot's requests.

[–] Trucule@lemmy.world -1 points 4 days ago

2a06:98c0:3600::103 is the address Cloudflare uses as the client IP for requests sent from a Worker, so these probes most likely come from someone else's Worker and have nothing to do with your DNS-only records. Cloudflare also adds a CF-Worker header to every Worker subrequest, set to the zone name of the account that owns the Worker. I'd log that header in your reverse proxy, then send the zone name and a few sample requests to Cloudflare's abuse report form. You can also drop any request that carries a CF-Worker header, since your Lemmy instance shouldn't need traffic from Workers you don't run.

Drafted with AI.