• Hello everyone.

    I am from CleanTalk team, Security plugin developer.

    We have been reported about the issue of DDoS protection fired of reason of lot of request that contains

    lscwp_ctrl=before_optm

    We inspected the case and spotted that all the request were called from IP 50.116.62.225.

    We suppose, that the requests are a part of LiteSpeed remote cron jobs related to UCSS or CCSS? generation control.

    If we ride this correctly, please, help us to prevent DDoS protection fired for this service.

    • If you can confirm that this IP is concerned to LiteSpeed services, we would globally whitelist it for all the CleanTalk users.
    • If there could be more additional IP addresses / AS / Networks could be whitelitsed for this case, please provide them.
    • If there is no relation of LiteSpeed services with this ip, we will appreciate your advice how we can detect the source.
    • If the topic is not available to public conversation, please, provide any applicable contact info.

    Thank you.

  • You must be logged in to reply to this topic.