Welcome to Admin Junkies, Guest — join our community!

Register or log in to explore all our content and services for free on Admin Junkies.

CloudFlare WAF for blocking ASN's

Joined
Dec 22, 2022
Messages
2,118
Website
astrowhat.com
Credits
3,671
One feature I love about CF is the ability to block entire ASN's as well as specific IPs.
A few of the more recent that I have added as I get a LOT o "crap" from servers in their data centers (and since those aren't users, I don't have issues with blocking the entire ASN) are:
132203 (TENCENT-NET-AP-CN - China)
45899 (VNNIC-ASBLOCK-VN - Vietnam)
50565 (MuzafferGuler - Turkey)
135407 (TES-PL-AS-AP - Pakistan)
208312 (Red Byte LLC - Russia)
35913 (DEDIPATH-LLC - United States)
149428 (CODE200-AS-AP - Lithuania)
21859 (ZEN-ECN - United States)
22363 (POWER157 - United States)
136557 (HOST-AS-AP - Australia)

I don't do a full block... but they do have to go through a interactive challenge to get to the site. Since I've done this, a lot of my 404 errors (tracked by an add-on) to the site have bit the big one.
These are some of the attempts that have been presented:

Screen Shot 2023-06-15 at 3.06.01 AM.png
Screen Shot 2023-06-15 at 3.06.22 AM.png
Screen Shot 2023-06-15 at 3.06.37 AM.png
Screen Shot 2023-06-15 at 3.11.05 AM.png





Many of these are simply bots running out of data centers looking for an ingress point. With CF, you can block them totally or allow access based upon certain criteria.
Just to give an idea... I implemented these about 2 days ago.

Screen Shot 2023-06-15 at 3.22.34 AM.png




I run the "good bots" on CF, but anything else that is being used, I really don't want wasting the time of my site.

So, what ASN's have you blocked?
 
Advertisement Placeholder
A few more

36352 (AS-COLOCROSSING - United States)
54538 (Palo Alto Networks - US) apparently a "security" company that scans scans/spams your site
58057 (SecureBit AG - CH -Switzerland) - apparently another "security" company that loves to scan sites
55286 (B2 Net Solutions - CA) Yet another data center that really has NO reason to be interacting with your site
212238 (DataCamp Limited - UK) a VPN provider that has a spam history
9009 (M247 Europe) another VPN provider
203020 (HostRoyale Technologies Pvt Ltd - India)
14061 (Digital Ocean - Singapore) - IP 157.230.249.54 scanning for WordPress vulnerabilities, likely a Script-Kiddies bot
 

Log in or register to unlock full forum benefits!

Log in or register to unlock full forum benefits!

Register

Register on Admin Junkies completely free.

Register now
Log in

If you have an account, please log in

Log in
Who read this thread (Total readers: 0)
No registered users viewing this thread.

Would You Rather #9

  • Start a forum in a popular but highly competitive niche

    Votes: 9 27.3%
  • Initiate a forum within a limited-known niche with zero competition

    Votes: 24 72.7%
Win this space by entering the Website of The Month Contest

Theme editor

Theme customizations

Graphic Backgrounds

Granite Backgrounds