4 ms·
Nearly 90% of HTTP attacks on our website come from Cloudflare Workers. We've chosen to block huge subnets of their IPs because of it. This new raw TCP connec
by sparrish 3y ago
Nearly 90% of HTTP attacks on our website come from Cloudflare Workers. We've chosen to block huge subnets of their IPs because of it.
This new raw TCP connection feature will undoubtedly be used to attack other services in similar ways.
- spacetime_cmplx 3y agoThat's concerning. Could you elaborate on how you identified the traffic as cloudflare workers? Also, what sorts of HTTP attacks? wp-admin probes? Plain DDoS? Cloudflare has (had?) a murky history with not taking down DDoS for hire services ironically hosted behind cloudflare. But while you could argue they had an incentive to do that (sell protection), I can't think of any incentive to let Workers be abused.
- capableweb 3y ago> Could you elaborate on how you identified the traffic as cloudflare workers? Trivial based on the fact that HTTP requests coming from CloudFlare Workers has a cf-worker header. Also, any traffic coming from cloudflare-owned IP blocks clearly belongs to cloudflare and can be safely blocked.
- InvaderFizz 3y agoOn the second point, with the introduction of Cloudflare WARP VPN, that's not quite true. Additionally, I believe Safari Private Relay may end up looking like it originates from CF as well.
- ignoramous 3y ago> Additionally, I believe Safari Private Relay may end up looking like it originates from CF as well. Cloudflare reserves IP ranges just for Private Relay: https://developer.apple.com/support/prepare-your-network-for-icloud-private-relay/ https://developer.apple.com/support/prepare-your-network-for...
- KomoD 3y ago> and can be safely blocked. Well no, not if you yourself are also using Cloudflare
- capableweb 3y agoYou mean like server<>server communication? Hopefully that communication stays within the network rather than going from server<>internet<>server
- KomoD 3y agoI mean if you are using Cloudflare with their proxy, so origin<>cloudflare<>client
- capableweb 3y agoYeah, then you'd just block based on the client IP which is in a header, rather than the IP on the connection.
- Manouchehri 3y agoYou can block third party Workers with a CF WAF rule. Here's an example: cf.worker.upstream_zone ne "" and not cf.worker.upstream_zone in {"aimoda.workers.dev" "ai.moda"}
- iampims 3y agoIf you can afford to block at L7, all outgoing http requests from Cloudflare workers have a HTTP header identifying them as such. Link: https://developers.cloudflare.com/fundamentals/get-started/reference/http-request-headers/ https://developers.cloudflare.com/fundamentals/get-started/r... cf-worker: example.com