Loading video...

Video Failed to Load

Go Home

Pro tip: add a Cloudflare WAF rule to block common scanner paths like .env, .git, wp-login they get blocked at the edge and never touch your server

256,686 views • 5 months ago •via X (Twitter)

77 Comments

Venelin K.'s profile picture
Venelin K.5 months ago

here's the full list of paths I'm blocking feel free to grab it 👇

Marcus Gill Greenwood's profile picture
Marcus Gill Greenwood5 months ago

Better still you can 302 redirect them to these very large files. Script kiddies will really appreciate that

Venelin K.'s profile picture
Venelin K.5 months ago

haha, this sounds brutal ... the 10GB bin, lol :D

Ilyas's profile picture
Ilyas5 months ago

The Managed Rulesets already block most of these requests, and tools like allow you to block the remaining requests

Venelin K.'s profile picture
Venelin K.5 months ago

nice, didn't know about flarehawk

Tuginho's profile picture
Tuginho5 months ago

you can copy and insert this into the expression box: there are some paths related to laravel, ask claude to extend this for your framework if you want

Venelin K.'s profile picture
Venelin K.5 months ago

nice, this list covers lots of scanners. thanks for sharing!

Kay's profile picture
Kay5 months ago

40% is actually really good for early-stage rate limiting. most people don't add any and wonder why their login endpoints get hammered. what are you using, fail2ban or something custom?

Venelin K.'s profile picture
Venelin K.5 months ago

yeah cloudflare + fail2ban with custom rules

Bartek Igielski's profile picture
Bartek Igielski5 months ago

switch it to "matches regex" and use this /(\.php|wp-|[/.]env|\.git|\.vscode|\.idea|\.ds_store|\.ht(access|passwd)|pma|phpmyadmin|config|setup|install|cgi-bin|etc\/passwd|proc\/self|actuator|jolokia|heapdump|\.aws\/|\.ssh\/|xmlrpc)/i less clicking and wider coverage

Venelin K.'s profile picture
Venelin K.5 months ago

I can't block .php completely... it's a php app :D but good alternative as well, thanks for sharing!

Roman Shalabanov's profile picture
Roman Shalabanov5 months ago

@Igloczek Do your URIs actually include .php? I don’t think they do, since your project isn’t built with pure PHP. The routes are clear without .php, so blocking it shouldn’t cause any issues.

Venelin K.'s profile picture
Venelin K.5 months ago

@Igloczek yeah, you're right but I don't want to block .php just in case, so it may cause some other issues Maybe I can test on a different app, but for production I'm afraid to block them all :D

Trevor I. Lasn's profile picture
Trevor I. Lasn5 months ago

this plus auto-ban is the real combo. i ban any IP that triggers 20+ blocked paths per minute. the scanner traffic drops to basically zero

Venelin K.'s profile picture
Venelin K.5 months ago

yes, I applied the same rules 20+ scans for 1 minute -> fail2ban for 1 day + Cloudflare WAF block it's very effective

Johan Guse's profile picture
Johan Guse5 months ago

Hey, it will be very helpful if you could add these texts rules to a gist

Venelin K.'s profile picture
Venelin K.5 months ago

good idea, here you go

Butch Ewing's profile picture
Butch Ewing5 months ago

I also wonder why Cloudflare doesn't do this by default.

Venelin K.'s profile picture
Venelin K.5 months ago

yeah, it would be very helpful, if you can just toggle this by default :D

David's profile picture
David5 months ago

Would just safe a bunch of 404 requests so not that big of a deal imho

Venelin K.'s profile picture
Venelin K.5 months ago

but still hitting your web server, I don't want this

ethan's profile picture
ethan5 months ago

Most of these are setup by default

Venelin K.'s profile picture
Venelin K.5 months ago

where?

ethan's profile picture
ethan5 months ago

Docs

Venelin K.'s profile picture
Venelin K.5 months ago

sure

Csaba Kissi's profile picture
Csaba Kissi5 months ago

I use it on all my sites. It significantly reduces bandwidth usage and makes your site more secure.

Venelin K.'s profile picture
Venelin K.5 months ago

yeah and also the load on the server. I've added it yesterday and blocks like crazy

Kay's profile picture
Kay5 months ago

this plus rate-limiting on login endpoints. cloudflare catches scanner noise but people forget that their /login is hammered just as much. add a turnstile and watch the abuse drop off a cliff

Venelin K.'s profile picture
Venelin K.5 months ago

yep, already done that and blocks 40% of the login requests.

Agent Mish's profile picture
Agent Mish5 months ago

Great tip, straight to the point and useful. Thank you

Venelin K.'s profile picture
Venelin K.5 months ago

you're welcom, glad it's helpful

DELA's profile picture
DELA5 months ago

Can I do this on @BunnyCDN as well?

Venelin K.'s profile picture
Venelin K.5 months ago

@BunnyCDN I'm not familiar with their UI, but if they have a WAF, yeah you can do it

Mohammad Shoeb's profile picture
Mohammad Shoeb5 months ago

Gem!

Venelin K.'s profile picture
Venelin K.5 months ago

thank you

Avieshek's profile picture
Avieshek5 months ago

ELI5?

Venelin K.'s profile picture
Venelin K.5 months ago

bots always scan your site for files like .env, .git, wp-login etc trying to find vulnerabilities add a cloudflare firewall rule to block these paths and they get stopped at the edge before they ever reach your server make sense now?

Avieshek's profile picture
Avieshek5 months ago

Thank you, is this deployable for CloudFlare Zero Trust Firewall Policies or just for site?

Venelin K.'s profile picture
Venelin K.5 months ago

I've added it to the WAF rules, but maybe it will work with Zero Trust... hadn't test it

Avieshek's profile picture
Avieshek5 months ago

WordPress Login as well?

IP's profile picture
IP5 months ago

oh, that's cool, thatns for the reminder

Shefali's profile picture
Shefali5 months ago

Thanks for sharing, Venelin!

Venelin K.'s profile picture
Venelin K.5 months ago

welcome, Shefali... hope it's helpful :-)

Aleksandar Janca's profile picture
Aleksandar Janca5 months ago

smart will do it tomorrow thanks

Orgest's profile picture
Orgest5 months ago

Wow great. Thank you!

Kinder • Grinder's profile picture
Kinder • Grinder5 months ago

Thanks, that's great advice.

Venelin K.'s profile picture
Venelin K.5 months ago

you're welcom, glad it's helpful

Priyanshu.dev's profile picture
Priyanshu.dev5 months ago

What if someone doesn't want to use cloudflare and configure these things on their own VPS like Hetzner, Ovhclould or any platform which has no built-in setup. Is there any way to prevent scanning there too like configuration of nginx or what to add these security?

Venelin K.'s profile picture
Venelin K.5 months ago

yes, fail2ban with custom rules example: 3 of these requests in 1 minute, then ban the IP for 1 day you can configure and adjust

Priyanshu.dev's profile picture
Priyanshu.dev5 months ago

Ok, will try 👍

Kim Hudaya's profile picture
Kim Hudaya5 months ago

Thank you so much, I got approximately thousands requests like this everyday, crazy that CF by default not blocking them

Venelin K.'s profile picture
Venelin K.5 months ago

yeah same here, that's why I added these rules

Ganja's profile picture
Ganja5 months ago

managed rules already do this, just enable them brah

Venelin K.'s profile picture
Venelin K.5 months ago

which rule does the same?

Lars LJ's profile picture
Lars LJ5 months ago

You blocking core WP paths?

Venelin K.'s profile picture
Venelin K.5 months ago

yes, because my app is not WP

Lars LJ's profile picture
Lars LJ5 months ago

Gotcha 👌

Mo's profile picture
Mo5 months ago

Plus Plus captcha or turnstile ✅

Venelin K.'s profile picture
Venelin K.5 months ago

yep, turstile is mandatory

Qnoox's profile picture
Qnoox5 months ago

cloudflare should just add this by default..

Venelin K.'s profile picture
Venelin K.5 months ago

yes!

Touqeer Shafi's profile picture
Touqeer Shafi5 months ago

Is this on the free version or on the paid version?

Venelin K.'s profile picture
Venelin K.5 months ago

free version... you have 5 rules

Rahul Gupta's profile picture
Rahul Gupta5 months ago

thanks for the tip

Venelin K.'s profile picture
Venelin K.5 months ago

welcome, glad it's helpful

SG's profile picture
SG5 months ago

I don't think this is needed. You shouldn't make those public in the first place, not even accidentally.

Venelin K.'s profile picture
Venelin K.5 months ago

@sanchogodinho why?

SG's profile picture
SG5 months ago

If they expose basic stuff like this, they most probably don't know to write secure code. Most big companies don't really use WAF to block these routes.

Venelin K.'s profile picture
Venelin K.5 months ago

@sanchogodinho haha ok... but I'm not a big company... solo dev here this is helpful and I want to share it, ok? :D

Saïd Aitmbarek's profile picture
Saïd Aitmbarek5 months ago

damn cool, i'll copy your gist in CF WAF thanks Ven. :)

Venelin K.'s profile picture
Venelin K.5 months ago

you're welcome mate, hope it helps!

Liew CheonFong's profile picture
Liew CheonFong5 months ago

For non WordPress site

Venelin K.'s profile picture
Venelin K.5 months ago

yep

Pedro Moranga's profile picture
Pedro Moranga5 months ago

Basic tip

Venelin K.'s profile picture
Venelin K.5 months ago

but it works :D

Ju's profile picture
Ju5 months ago

Thanks a lot. My webservers only accept cloudflare reverse proxy requests. This will harden it even more ✊🏼

Venelin K.'s profile picture
Venelin K.5 months ago

💯

Related Videos