I do not have mod_Cloudflare is not installed; what does this do?
The IPs are:
162.158.126.0 and 108.162.219.0
Both were identically on timing and using the same username. There was 258 requests all within a 10 minute window. The username they were using does not exist – in fact, we don’t use usernames, the system is designed for emails only.
My only concern is, why did this happen when this security I have setup is suppose to stop that.
To add to this; the server is using Litespeed. Don’t think mod_Cloudflare will work.
What security system or plugin is that? IPs never end in .0, so an attacker could potentially be sending a fake X-Forwarded-For header or something of the sorts to throw off your software.
That is Simple History that tracks and records everything. The only thing is, even if it is a fake IP, how did they get by Cloudflare “I am under attack”. I will leave this for now as I haven’t see them since back. Before I got tons of these. Just strange that one came in like that after running this for 24 hours.