We are using WHM in a Dedicated Server at Hostgator, we have 50% of our domains in Cloudflare Free Plan . the Csf is been installed, and I asked Hostgator to add the "mod_cloudflare" also i whitelisted the Cloudflare ip in csf.allow. (in the server check the mod_cloudflare is green and says "OK" the apache status)
but i'm still receiving email from lfd saying that the IP where is come from the attack is cloudflare.
this is a sample of the email
It says "(IP match in csf.allow, block may not work)"Time: Tue Jan 3 01:37:46 2017 -0600
IP: 108.162.229.181 (FR/France/-)
Failures: 4 (mod_security)
Interval: 3600 seconds
Blocked: Temporary Block (IP match in csf.allow, block may not work)
Log entries:
[Tue Jan 03 00:44:20.025308 2017] [:error] [pid 4927:tid 139832997103360] [client 108.162.229.181] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^Mozilla\\\\/4\\\\.0 \\\\(compatible:" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "8"] [id "900205"] [msg "XMLRPC Request UA used in DDOS"] [hostname "painlessstopsmoking.com"] [uri "/xmlrpc.php"] [unique_id "WGtIRMYBUNUAABM-nFkAAACW"]
[Tue Jan 03 00:59:23.580885 2017] [:error] [pid 4927:tid 139833282131712] [client 108.162.229.181] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^Mozilla\\\\/4\\\\.0 \\\\(compatible:" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "8"] [id "900205"] [msg "XMLRPC Request UA used in DDOS"] [hostname "painlessstopsmoking.com"] [uri "/xmlrpc.php"] [unique_id "WGtLy8YBUNUAABM-ntoAAACC"]
[Tue Jan 03 01:26:44.549118 2017] [:error] [pid 21970:tid 139833122981632] [client 108.162.229.181] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^Mozilla\\\\/4\\\\.0 \\\\(compatible:" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "8"] [id "900205"] [msg "XMLRPC Request UA used in DDOS"] [hostname "painlessstopsmoking.com"] [uri "/xmlrpc.php"] [unique_id "WGtSNMYBUNUAAFXSfLYAAAFK"]
[Tue Jan 03 01:37:43.406692 2017] [:error] [pid 21970:tid 139832976123648] [client 108.162.229.181] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^Mozilla\\\\/4\\\\.0 \\\\(compatible:" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "8"] [id "900205"] [msg "XMLRPC Request UA used in DDOS"] [hostname "painlessstopsmoking.com"] [uri "/xmlrpc.php"] [unique_id "WGtUx8YBUNUAAFXSfowAAAFY"]
I used to receive 5-10 attacks daily with this kind of issue
so what should I do in order to resolve this issue? it's a CSF issue? a bug?
Thanks For The Help!