Big ddos atack in my 5 day website

What is the name of the domain?

Rentals.az

What is the issue you’re encountering

DDOS

What steps have you taken to resolve the issue?

I used any filters in WAF but it is not help me. i m blocked all country wit WAF

Was the site working with SSL prior to adding it to Cloudflare?

Yes

What is the current SSL/TLS setting?

Flexible

What are the steps to reproduce the issue?

I need help. i dont now how defuse ddos attack. if i buy pro packet 25 usd in month cloudflare help me?

May I ask what do you see under the Security → Events, for the service which was triggered ?

When you click on a particular one, does it say l7 http ddos or something else?

You should be able to see the challenged or blocked event under the Security tab → Events at Cloudflare dashboard for your zone and know exactly which security option was triggered.

Did you created a Custom WAF rule?
If so, could you share a screenshot of it?
What happens when you disable it? Does your Website work or not?

Have you got any information from your log files of your Web server about attack from the IP addresses?

i cant upload media in post becouse new member

[grid]


more screen


waf rule

website work my hosting blocked somethsing

Thank you for feedback.

Could you navigate to the Security → Events tab instead of Analytics tab? :thinking:

You’ve added it after you’ve figured out a lot of events? :thinking:

So you’ve decided to give it a try and stop DDoS with custom WAF rule.

May I ask you to check below post for help, just in case:

events tab

Thank you for sharing screenshots and feedback.

May I ask if you’ve used your domain name possibly as a VPN service endpoint such as vpn.yourdomain.com since before? :thinking:

no, i download wordpress theme for wordpress and make odify in site, after hosting provider says me i m under attack use please Cloudflare. and 12 hours im inder attack

Purchasing Pro plan could help to battle and prevent more attacks coming, however in long-term you might have to set some WAF rules then as follows from below posts.

If I may add here as a really good reference for further cases in terms of security and protection with Cloudflare from my colleague @jnperamo:

We can lock down our web host and allow only the Cloudflare to connect and similar techniques:

We can use Cloudflare Access / Zero Trust (Teams) for WP Admin login:

Sharing some useful stuff here:


screen one more

Thank you for sharing. It seems to be quite heavy attack.
Keep proxied :orange: and tune-up your security settings using above posts.

Keep in mind to disable most popular way for DDoS such as xmlrpc.php and few others for WordPress website.

Hopefully your theme or plugin is not nulled one and doesn’t contain some malicious code or has some kind of a malware? :thinking:

Alongside Cloudflare and your current situation, I’d suggest at least having some plugin for security such as lightweight BBQ:

Or Wordfence:

if i buy pro packet you help me?

I’ve been trying to do something with the firewall for 4 hours, I blocked get and post requests, blocked the IP, but it doesn’t stop. I don’t understand much. If I buy PRO pocket, can you stop it?

hm.i doünload free theme and name theme treveller nulled

From my understanding, it is nulled? If true, then it might be a reason why you got DDoS then if some script in the background is executing some bad code causing such issue :thinking:

Please don’t use nulled themes or plugins due to your security and protection of your Website, hosting provider and your Website visitors in future.

Consider changing your database and user password and your WordPress user credentials, also check the CHMOD over directories in wp-content folder including all of the plugins and uploads too.

https://www.hostpapa.com/blog/security/what-to-do-if-your-wordpress-website-was-hacked/

https://www.getastra.com/blog/911/how-to-remove-the-backdoor-php-apiword-malware-from-your-wordpress-website/

2 Likes

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.