Cloudflare DNS being abused to attack other servers

What is the name of the domain?

http://zes2.top/ http://jacare.top/ http://zeb2.top/ http://newsmarters.top/

What is the issue you’re encountering

Someone is using cloudflares DNS service to point 4 domains at our server. If you look up any of these domains you can see they use cloudflares DNS. They are sending 100s attacks a minute all using cloudflares IP address

What steps have you taken to resolve the issue?

We cannot block 100s of IPs attacking our server from misusing cloudflares dns service. CLOUDFLARE needs to block these domains from using their service. This has been going on for a month and cloudflares support and service has been awful. i don’t know why anyone would use cloudflare when they can’t fix their own issues.

What feature, service or problem is this related to?

DNS records

What are the steps to reproduce the issue?

these ips are attacking our server

108.162.241.117
108.162.241.127
108.162.241.146
108.162.241.147
108.162.241.190
108.162.241.200
108.162.241.201
108.162.241.236
108.162.241.237
108.162.241.241
108.162.241.81
108.162.241.94
108.162.241.95
108.162.241.97
108.162.242.107
108.162.242.108
108.162.242.35
108.162.242.36
108.162.242.47
108.162.242.63
108.162.242.67
108.162.242.87
108.162.242.88
108.162.242.94
172.69.130.10
172.69.130.102
172.69.130.103
172.69.130.104
172.69.130.105
172.69.130.11
172.69.130.114
172.69.130.115
172.69.130.116
172.69.130.117
172.69.130.148
172.69.130.149
172.69.130.160
172.69.130.161
172.69.130.206
172.69.130.207
172.69.130.208
172.69.130.209
172.69.130.218
172.69.130.219
172.69.130.221
172.69.130.252
172.69.130.253
172.69.130.42
172.69.130.43
172.69.130.54
172.69.130.55
172.69.130.56
172.69.130.57
172.69.214.138
172.69.214.139
172.69.214.14
172.69.214.15
172.69.214.152
172.69.214.153
172.69.214.166
172.69.214.167
172.69.214.180
172.69.214.181
172.69.214.194
172.69.214.195
172.69.214.212
172.69.214.213
172.69.214.228
172.69.214.229
172.69.214.242
172.69.214.30
172.69.214.31
172.69.214.53
172.69.214.67
172.69.214.81
172.69.214.96
172.70.80.107
172.70.80.118
172.70.80.119
172.70.80.150
172.70.80.151
172.70.80.163
172.70.80.192
172.70.80.193
172.70.80.196
172.70.80.197
172.70.80.203
172.70.80.212
172.70.80.222
172.70.80.223
172.70.80.24
172.70.80.25
172.70.80.34
172.70.80.35
172.70.80.44
172.70.80.45
172.70.80.55
172.70.80.64
172.70.80.65
172.70.80.74
172.70.80.75
172.70.80.86
172.70.80.90
172.70.80.96
172.70.80.97
172.71.120.13
172.71.120.14

What is the name of the domain?

http://zes2.top/ http://jacare.top/ http://newsmarters.top/

What is the error number?

Someone is using cloudflares DNS service to point 4 domains at our server. If you look up any of these domains you can see they use cloudflares DNS. They are sending 100s attacks a minute all using cloudflares IP address What steps have you taken to resolve the issue?

What is the error message?

We cannot block 100s of IPs attacking our server from misusing cloudflares dns service. CLOUDFLARE needs to block these domains from using their service. This has been going on for a month and cloudflares support and service has been awful. i don’t know why anyone would use cloudflare when they can’t fix their own issues. What feature, service or problem is this related to?

What is the issue you’re encountering

We cannot block 100s of IPs attacking our server from misusing cloudflares dns service. CLOUDFLARE needs to block these domains from using their service. This has been going on for a month and cloudflares support and service has been awful. i don’t know why anyone would use cloudflare when they can’t fix their own issues. What feature, service or problem is this related to?

What steps have you taken to resolve the issue?

these ips are attacking our server

108.162.241.117
108.162.241.127
108.162.241.146
108.162.241.147
108.162.241.190
108.162.241.200
108.162.241.201
108.162.241.236
108.162.241.237
108.162.241.241
108.162.241.81
108.162.241.94
108.162.241.95
108.162.241.97
108.162.242.107
108.162.242.108
108.162.242.35
108.162.242.36
108.162.242.47
108.162.242.63
108.162.242.67
108.162.242.87
108.162.242.88
108.162.242.94
172.69.130.10
172.69.130.102
172.69.130.103
172.69.130.104
172.69.130.105
172.69.130.11
172.69.130.114
172.69.130.115
172.69.130.116
172.69.130.117
172.69.130.148
172.69.130.149
172.69.130.160
172.69.130.161
172.69.130.206
172.69.130.207
172.69.130.208
172.69.130.209
172.69.130.218
172.69.130.219
172.69.130.221
172.69.130.252
172.69.130.253
172.69.130.42
172.69.130.43
172.69.130.54
172.69.130.55
172.69.130.56
172.69.130.57
172.69.214.138
172.69.214.139
172.69.214.14
172.69.214.15
172.69.214.152
172.69.214.153
172.69.214.166
172.69.214.167
172.69.214.180
172.69.214.181
172.69.214.194
172.69.214.195
172.69.214.212
172.69.214.213
172.69.214.228
172.69.214.229
172.69.214.242
172.69.214.30
172.69.214.31
172.69.214.53
172.69.214.67
172.69.214.81
172.69.214.96
172.70.80.107
172.70.80.118
172.70.80.119
172.70.80.150
172.70.80.151
172.70.80.163
172.70.80.192
172.70.80.193
172.70.80.196
172.70.80.197
172.70.80.203
172.70.80.212
172.70.80.222
172.70.80.223
172.70.80.24
172.70.80.25
172.70.80.34
172.70.80.35
172.70.80.44
172.70.80.45
172.70.80.55
172.70.80.64
172.70.80.65
172.70.80.74
172.70.80.75
172.70.80.86
172.70.80.90
172.70.80.96
172.70.80.97
172.71.120.13
172.71.120.14

If you think those domains are pointed at your server IP address maliciously, you can report here…
https://abuse.cloudflare.com

Do you use Cloudflare yourself? If not, then you can block the requests at your firewall for these IP addresses…

If you do use Cloudflare for your site then…

  • restore visitor IPs so you can see the real source IP address of the clients at your origin
  • consider using a random IPv6 address from a /64 block for your origin instead of IPv4 or any IP addresses that were previously public so your origin IP address is hard to find
  • use Authenticated Origin Pull with your own certificate so only requests from your own zone on Cloudflare will be accepted by your origin
2 Likes

We cannot block those IPs or we block our clients legitimate cloudflare dns accounts. We have many clients that use cloudflare dns services. Blocking those ips would prevent our clients websites from displaying. (we already tried this).

I am instructing all my clients to stop using cloudflare since cloudflare cannot control their services from being abused.

We need cloudflare to step in and protect legitimate users.

also note I did report the abuse a week ago with no response. we continue to get bombarded with cloudflare IP addresses.

Please take the time to read the two documentation guides that @sjr linked. Both are important steps that will help you secure your server. For the authenticated origin pulls, it could be worth using individual self-generated certificates for additional protection.

Duplicate here

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.