Video yükleniyor...

Video Yüklenemedi

Ana Sayfaya Dön

Pro tip: add a Cloudflare WAF rule to block common scanner paths like .env, .git, wp-login they get blocked at the edge and never touch your server

256,686 görüntüleme • 5 ay önce •via X (Twitter)

77 Yorum

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

here's the full list of paths I'm blocking feel free to grab it 👇

Marcus Gill Greenwood profil fotoğrafı
Marcus Gill Greenwood5 ay önce

Better still you can 302 redirect them to these very large files. Script kiddies will really appreciate that

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

haha, this sounds brutal ... the 10GB bin, lol :D

Ilyas profil fotoğrafı
Ilyas5 ay önce

The Managed Rulesets already block most of these requests, and tools like allow you to block the remaining requests

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

nice, didn't know about flarehawk

Tuginho profil fotoğrafı
Tuginho5 ay önce

you can copy and insert this into the expression box: there are some paths related to laravel, ask claude to extend this for your framework if you want

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

nice, this list covers lots of scanners. thanks for sharing!

Kay profil fotoğrafı
Kay5 ay önce

40% is actually really good for early-stage rate limiting. most people don't add any and wonder why their login endpoints get hammered. what are you using, fail2ban or something custom?

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

yeah cloudflare + fail2ban with custom rules

Bartek Igielski profil fotoğrafı
Bartek Igielski5 ay önce

switch it to "matches regex" and use this /(\.php|wp-|[/.]env|\.git|\.vscode|\.idea|\.ds_store|\.ht(access|passwd)|pma|phpmyadmin|config|setup|install|cgi-bin|etc\/passwd|proc\/self|actuator|jolokia|heapdump|\.aws\/|\.ssh\/|xmlrpc)/i less clicking and wider coverage

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

I can't block .php completely... it's a php app :D but good alternative as well, thanks for sharing!

Roman Shalabanov profil fotoğrafı
Roman Shalabanov5 ay önce

@Igloczek Do your URIs actually include .php? I don’t think they do, since your project isn’t built with pure PHP. The routes are clear without .php, so blocking it shouldn’t cause any issues.

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

@Igloczek yeah, you're right but I don't want to block .php just in case, so it may cause some other issues Maybe I can test on a different app, but for production I'm afraid to block them all :D

Trevor I. Lasn profil fotoğrafı
Trevor I. Lasn5 ay önce

this plus auto-ban is the real combo. i ban any IP that triggers 20+ blocked paths per minute. the scanner traffic drops to basically zero

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

yes, I applied the same rules 20+ scans for 1 minute -> fail2ban for 1 day + Cloudflare WAF block it's very effective

Johan Guse profil fotoğrafı
Johan Guse5 ay önce

Hey, it will be very helpful if you could add these texts rules to a gist

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

good idea, here you go

Butch Ewing profil fotoğrafı
Butch Ewing5 ay önce

I also wonder why Cloudflare doesn't do this by default.

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

yeah, it would be very helpful, if you can just toggle this by default :D

David profil fotoğrafı
David5 ay önce

Would just safe a bunch of 404 requests so not that big of a deal imho

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

but still hitting your web server, I don't want this

ethan profil fotoğrafı
ethan5 ay önce

Most of these are setup by default

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

where?

ethan profil fotoğrafı
ethan5 ay önce

Docs

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

sure

Csaba Kissi profil fotoğrafı
Csaba Kissi5 ay önce

I use it on all my sites. It significantly reduces bandwidth usage and makes your site more secure.

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

yeah and also the load on the server. I've added it yesterday and blocks like crazy

Kay profil fotoğrafı
Kay5 ay önce

this plus rate-limiting on login endpoints. cloudflare catches scanner noise but people forget that their /login is hammered just as much. add a turnstile and watch the abuse drop off a cliff

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

yep, already done that and blocks 40% of the login requests.

Agent Mish profil fotoğrafı
Agent Mish5 ay önce

Great tip, straight to the point and useful. Thank you

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

you're welcom, glad it's helpful

DELA profil fotoğrafı
DELA5 ay önce

Can I do this on @BunnyCDN as well?

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

@BunnyCDN I'm not familiar with their UI, but if they have a WAF, yeah you can do it

Mohammad Shoeb profil fotoğrafı
Mohammad Shoeb5 ay önce

Gem!

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

thank you

Avieshek profil fotoğrafı
Avieshek5 ay önce

ELI5?

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

bots always scan your site for files like .env, .git, wp-login etc trying to find vulnerabilities add a cloudflare firewall rule to block these paths and they get stopped at the edge before they ever reach your server make sense now?

Avieshek profil fotoğrafı
Avieshek5 ay önce

Thank you, is this deployable for CloudFlare Zero Trust Firewall Policies or just for site?

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

I've added it to the WAF rules, but maybe it will work with Zero Trust... hadn't test it

Avieshek profil fotoğrafı
Avieshek5 ay önce

WordPress Login as well?

IP profil fotoğrafı
IP5 ay önce

oh, that's cool, thatns for the reminder

Shefali profil fotoğrafı
Shefali5 ay önce

Thanks for sharing, Venelin!

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

welcome, Shefali... hope it's helpful :-)

Aleksandar Janca profil fotoğrafı
Aleksandar Janca5 ay önce

smart will do it tomorrow thanks

Orgest profil fotoğrafı
Orgest5 ay önce

Wow great. Thank you!

Kinder • Grinder profil fotoğrafı
Kinder • Grinder5 ay önce

Thanks, that's great advice.

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

you're welcom, glad it's helpful

Priyanshu.dev profil fotoğrafı
Priyanshu.dev5 ay önce

What if someone doesn't want to use cloudflare and configure these things on their own VPS like Hetzner, Ovhclould or any platform which has no built-in setup. Is there any way to prevent scanning there too like configuration of nginx or what to add these security?

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

yes, fail2ban with custom rules example: 3 of these requests in 1 minute, then ban the IP for 1 day you can configure and adjust

Priyanshu.dev profil fotoğrafı
Priyanshu.dev5 ay önce

Ok, will try 👍

Kim Hudaya profil fotoğrafı
Kim Hudaya5 ay önce

Thank you so much, I got approximately thousands requests like this everyday, crazy that CF by default not blocking them

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

yeah same here, that's why I added these rules

Ganja profil fotoğrafı
Ganja5 ay önce

managed rules already do this, just enable them brah

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

which rule does the same?

Lars LJ profil fotoğrafı
Lars LJ5 ay önce

You blocking core WP paths?

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

yes, because my app is not WP

Lars LJ profil fotoğrafı
Lars LJ5 ay önce

Gotcha 👌

Mo profil fotoğrafı
Mo5 ay önce

Plus Plus captcha or turnstile ✅

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

yep, turstile is mandatory

Qnoox profil fotoğrafı
Qnoox5 ay önce

cloudflare should just add this by default..

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

yes!

Touqeer Shafi profil fotoğrafı
Touqeer Shafi5 ay önce

Is this on the free version or on the paid version?

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

free version... you have 5 rules

Rahul Gupta profil fotoğrafı
Rahul Gupta5 ay önce

thanks for the tip

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

welcome, glad it's helpful

SG profil fotoğrafı
SG5 ay önce

I don't think this is needed. You shouldn't make those public in the first place, not even accidentally.

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

@sanchogodinho why?

SG profil fotoğrafı
SG5 ay önce

If they expose basic stuff like this, they most probably don't know to write secure code. Most big companies don't really use WAF to block these routes.

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

@sanchogodinho haha ok... but I'm not a big company... solo dev here this is helpful and I want to share it, ok? :D

Saïd Aitmbarek profil fotoğrafı
Saïd Aitmbarek5 ay önce

damn cool, i'll copy your gist in CF WAF thanks Ven. :)

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

you're welcome mate, hope it helps!

Liew CheonFong profil fotoğrafı
Liew CheonFong5 ay önce

For non WordPress site

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

yep

Pedro Moranga profil fotoğrafı
Pedro Moranga5 ay önce

Basic tip

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

but it works :D

Ju profil fotoğrafı
Ju5 ay önce

Thanks a lot. My webservers only accept cloudflare reverse proxy requests. This will harden it even more ✊🏼

Venelin K. profil fotoğrafı
Venelin K.5 ay önce

💯

Benzer Videolar