I was reviewing my access.log and see many lines in my log file resembling the following. IP addresses redacted.
www.MyDomain.com #.#.#.# [01/Nov/2022:12:45:49 +0000] GET “/” HTTP/1.1 200 “https://www.MyDomain.com/?URL=http://RandomDomain.com/blahblahblah” “Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0” #.#.#.# “/index.php” – 5.67 14132 0.000 –
My architecture is setup with Sucuri as my WAF, with Kinsta/Cloudflare as my hosting provider.
WordPress is latest version, PHP is 8.1.
I’m trying to block these requests and want to understand what’s causing them. Can anyone provide insight here please?
[ad_2]