Tag: cloudflare

  • How to block PetalBot using Cloudflare

    How to block PetalBot using Cloudflare

    PetalBot is a website crawling bot of the Petal search engine. I have recently noticed in one of the news websites that I manage started getting a large number of requests from the bot. It kept getting worse, to the point that it started increasing the server load. So, I finally had to block the PetalBot using Cloudflare. Here is a step-by-step guide on how I did it.

    Block PetalBot using Web Application firewall :

    You can go to the WAF section under security and add the following firewall rule to block any User Agent which contains the name “PetalBot“. Please check the screenshot below to understand the firewall rule.

    Cloudflare Firewall rule to block User Agent that contains, “PetalBot” or “petalsearch”
  • How to restore the real IP address of the visitor if your web application is behind Cloudflare

    If your web application is behind Cloudflare and you try to access the IP address of the visitor in your application, it will always show Cloudflare IP addresses, to fix this, you need to replace the Cloudflare IP address with the real IP address of the respective visitor.

    Cloudflare IP addresses :

    First of all, you need to know the IP addresses of Cloudflare.

    How to restore the real IP of the visitor in the Nginx server:

    Add the following Nginx rules to restore the real IP addresses of the visitor.

    # Cloudflare IPv4 addresses  ( IPV4 addresses that you got from https://www.cloudflare.com/ips-v4 ) 
    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 131.0.72.0/22;
    
    # Cloudflare IPv6 addresses ( IPV6 addresses that you got from https://www.cloudflare.com/ips-v6 )
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2a06:98c0::/29;
    set_real_ip_from 2c0f:f248::/32;
    
    real_ip_header X-Forwarded-For;

    If you have multiple domains in a single Nginx server, then you have to make sure that the rules are applied globally on all the sites in the server or if it’s a single site, make sure that the rules are applied only for that particular web application.

  • 5 Simple rules in Cloudflare to Secure your WordPress website

    You can add an extra layer of security to your WordPress website using the Cloudflare service. Here is a list of rules that you can apply to your website in Cloudflare settings to improve security.

    Secure WordPress login page and administrator section

    Secure WordPress admin and login URL from bot attacks by making sure that you add rules as per the given screenshot below.

    Secure wp-login.php URL
    Secure WordPress admin section and disable cache

    Disable access to the xmlrpc.php file

    You can disable access to the xmlrpc.php file and allow only certain IP addresses. You may want to allow Jetpack or any other service.

    The AS Number 2636 is jetpack number, you can use it to whitelist jetpack services.

    You can copy the expression code below to implement the rule.

    (http.request.uri.path eq "/xmlrpc.php" and ip.geoip.asnum ne 2635)

    You can also completely block access to the xmlrpc.php file via the expression below.

    (http.request.uri.path contains "xmlrpc.php")
    Block xmlrpc.php file completely using Cloudflare firewall rule.

    You can also redirect any traffic to xmlrpc.php file to home page or any other URL using page rule.

    Block direct access to PHP files in the wp-content and wp-include folder

    Direct access of PHP file can be blocked in wp-content or wp-includes folder.

    Add Captcha or Challenge users who have a higher threat score

    Cloudflare has a Threat Score system, that gives a score to IP addresses based on their reputation. You can use it to block or challenge visitors with captcha. Use this option carefully not to block or discourage your real human visitors.

    Secure requests with “wp-“

    You can also secure any URL that has wp- , remember to put this rule below the wp-admin or wp-login.php RULE.

    Do you use any of the rules, or you have any questions? Let me know in the comment section 🙂