Scammers attacking domains attached to funnelish

Hey guys we are having a massive problem with scammers bypassing cloudflare and directly running hundreds of stolen credit cards on our funnelish domains.

Hired a cyber expert, and they said these scammers and the bot they are using is bypassing Cloudflare and all of its rules and directly exploiting Funnelish.

ONLY way to stop this would be to block all traffic that doesn’t pass through Cloudflare…

Does Funnelish have the ability to allow specific IP addresses and block others, so that we can only allow traffic that passes via Cloudflare ?

Any help is greatly appreciated! This situation has truly been a nightmare…

Hi @er1223 I hope you doing good,

I completely understand the urgency and frustration with scammers bypassing Cloudflare to exploit Funnelish.

To address this, yes, Funnelish should support IP filtering to restrict access only to traffic coming through Cloudflare. Here’s the solution I recommend:

  1. Block All Non-Cloudflare Traffic: We can set up IP whitelisting to only allow Cloudflare’s IP ranges. Cloudflare publishes their list of IP ranges that we can configure in Funnelish to block any direct traffic from scammers or bots bypassing Cloudflare.
  2. Use Web Application Firewall (WAF) and Security Rules: We can further configure Cloudflare’s WAF and set up more precise security rules to detect and block suspicious activities.

I can handle the entire setup for you to ensure your traffic flows only through Cloudflare, securing your funnel from malicious activity. Let me know if you’d like me to get started on this right away.

This will safeguard your site and give you peace of mind.

Best regards,
Abdulrehman Asif
[email protected]