Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

Pro tip: add a Cloudflare WAF rule to block common scanner paths like .env, .git, wp-login they get blocked at the edge and never touch your server

256,686 Aufrufe • vor 5 Monaten •via X (Twitter)

77 Kommentare

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

here's the full list of paths I'm blocking feel free to grab it 👇

Profilbild von Marcus Gill Greenwood
Marcus Gill Greenwoodvor 5 Monaten

Better still you can 302 redirect them to these very large files. Script kiddies will really appreciate that

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

haha, this sounds brutal ... the 10GB bin, lol :D

Profilbild von Ilyas
Ilyasvor 5 Monaten

The Managed Rulesets already block most of these requests, and tools like allow you to block the remaining requests

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

nice, didn't know about flarehawk

Profilbild von Tuginho
Tuginhovor 5 Monaten

you can copy and insert this into the expression box: there are some paths related to laravel, ask claude to extend this for your framework if you want

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

nice, this list covers lots of scanners. thanks for sharing!

Profilbild von Kay
Kayvor 5 Monaten

40% is actually really good for early-stage rate limiting. most people don't add any and wonder why their login endpoints get hammered. what are you using, fail2ban or something custom?

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

yeah cloudflare + fail2ban with custom rules

Profilbild von Bartek Igielski
Bartek Igielskivor 5 Monaten

switch it to "matches regex" and use this /(\.php|wp-|[/.]env|\.git|\.vscode|\.idea|\.ds_store|\.ht(access|passwd)|pma|phpmyadmin|config|setup|install|cgi-bin|etc\/passwd|proc\/self|actuator|jolokia|heapdump|\.aws\/|\.ssh\/|xmlrpc)/i less clicking and wider coverage

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

I can't block .php completely... it's a php app :D but good alternative as well, thanks for sharing!

Profilbild von Roman Shalabanov
Roman Shalabanovvor 5 Monaten

@Igloczek Do your URIs actually include .php? I don’t think they do, since your project isn’t built with pure PHP. The routes are clear without .php, so blocking it shouldn’t cause any issues.

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

@Igloczek yeah, you're right but I don't want to block .php just in case, so it may cause some other issues Maybe I can test on a different app, but for production I'm afraid to block them all :D

Profilbild von Trevor I. Lasn
Trevor I. Lasnvor 5 Monaten

this plus auto-ban is the real combo. i ban any IP that triggers 20+ blocked paths per minute. the scanner traffic drops to basically zero

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

yes, I applied the same rules 20+ scans for 1 minute -> fail2ban for 1 day + Cloudflare WAF block it's very effective

Profilbild von Johan Guse
Johan Gusevor 5 Monaten

Hey, it will be very helpful if you could add these texts rules to a gist

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

good idea, here you go

Profilbild von Butch Ewing
Butch Ewingvor 5 Monaten

I also wonder why Cloudflare doesn't do this by default.

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

yeah, it would be very helpful, if you can just toggle this by default :D

Profilbild von David
Davidvor 5 Monaten

Would just safe a bunch of 404 requests so not that big of a deal imho

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

but still hitting your web server, I don't want this

Profilbild von ethan
ethanvor 5 Monaten

Most of these are setup by default

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

where?

Profilbild von ethan
ethanvor 5 Monaten

Docs

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

sure

Profilbild von Csaba Kissi
Csaba Kissivor 5 Monaten

I use it on all my sites. It significantly reduces bandwidth usage and makes your site more secure.

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

yeah and also the load on the server. I've added it yesterday and blocks like crazy

Profilbild von Kay
Kayvor 5 Monaten

this plus rate-limiting on login endpoints. cloudflare catches scanner noise but people forget that their /login is hammered just as much. add a turnstile and watch the abuse drop off a cliff

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

yep, already done that and blocks 40% of the login requests.

Profilbild von Agent Mish
Agent Mishvor 5 Monaten

Great tip, straight to the point and useful. Thank you

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

you're welcom, glad it's helpful

Profilbild von DELA
DELAvor 5 Monaten

Can I do this on @BunnyCDN as well?

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

@BunnyCDN I'm not familiar with their UI, but if they have a WAF, yeah you can do it

Profilbild von Mohammad Shoeb
Mohammad Shoebvor 5 Monaten

Gem!

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

thank you

Profilbild von Avieshek
Avieshekvor 5 Monaten

ELI5?

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

bots always scan your site for files like .env, .git, wp-login etc trying to find vulnerabilities add a cloudflare firewall rule to block these paths and they get stopped at the edge before they ever reach your server make sense now?

Profilbild von Avieshek
Avieshekvor 5 Monaten

Thank you, is this deployable for CloudFlare Zero Trust Firewall Policies or just for site?

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

I've added it to the WAF rules, but maybe it will work with Zero Trust... hadn't test it

Profilbild von Avieshek
Avieshekvor 5 Monaten

WordPress Login as well?

Profilbild von IP
IPvor 5 Monaten

oh, that's cool, thatns for the reminder

Profilbild von Shefali
Shefalivor 5 Monaten

Thanks for sharing, Venelin!

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

welcome, Shefali... hope it's helpful :-)

Profilbild von Aleksandar Janca
Aleksandar Jancavor 5 Monaten

smart will do it tomorrow thanks

Profilbild von Orgest
Orgestvor 5 Monaten

Wow great. Thank you!

Profilbild von Kinder • Grinder
Kinder • Grindervor 5 Monaten

Thanks, that's great advice.

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

you're welcom, glad it's helpful

Profilbild von Priyanshu.dev
Priyanshu.devvor 5 Monaten

What if someone doesn't want to use cloudflare and configure these things on their own VPS like Hetzner, Ovhclould or any platform which has no built-in setup. Is there any way to prevent scanning there too like configuration of nginx or what to add these security?

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

yes, fail2ban with custom rules example: 3 of these requests in 1 minute, then ban the IP for 1 day you can configure and adjust

Profilbild von Priyanshu.dev
Priyanshu.devvor 5 Monaten

Ok, will try 👍

Profilbild von Kim Hudaya
Kim Hudayavor 5 Monaten

Thank you so much, I got approximately thousands requests like this everyday, crazy that CF by default not blocking them

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

yeah same here, that's why I added these rules

Profilbild von Ganja
Ganjavor 5 Monaten

managed rules already do this, just enable them brah

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

which rule does the same?

Profilbild von Lars LJ
Lars LJvor 5 Monaten

You blocking core WP paths?

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

yes, because my app is not WP

Profilbild von Lars LJ
Lars LJvor 5 Monaten

Gotcha 👌

Profilbild von Mo
Movor 5 Monaten

Plus Plus captcha or turnstile ✅

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

yep, turstile is mandatory

Profilbild von Qnoox
Qnooxvor 5 Monaten

cloudflare should just add this by default..

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

yes!

Profilbild von Touqeer Shafi
Touqeer Shafivor 5 Monaten

Is this on the free version or on the paid version?

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

free version... you have 5 rules

Profilbild von Rahul Gupta
Rahul Guptavor 5 Monaten

thanks for the tip

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

welcome, glad it's helpful

Profilbild von SG
SGvor 5 Monaten

I don't think this is needed. You shouldn't make those public in the first place, not even accidentally.

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

@sanchogodinho why?

Profilbild von SG
SGvor 5 Monaten

If they expose basic stuff like this, they most probably don't know to write secure code. Most big companies don't really use WAF to block these routes.

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

@sanchogodinho haha ok... but I'm not a big company... solo dev here this is helpful and I want to share it, ok? :D

Profilbild von Saïd Aitmbarek
Saïd Aitmbarekvor 5 Monaten

damn cool, i'll copy your gist in CF WAF thanks Ven. :)

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

you're welcome mate, hope it helps!

Profilbild von Liew CheonFong
Liew CheonFongvor 5 Monaten

For non WordPress site

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

yep

Profilbild von Pedro Moranga
Pedro Morangavor 5 Monaten

Basic tip

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

but it works :D

Profilbild von Ju
Juvor 5 Monaten

Thanks a lot. My webservers only accept cloudflare reverse proxy requests. This will harden it even more ✊🏼

Profilbild von Venelin K.
Venelin K.vor 5 Monaten

💯

Ähnliche Videos