正在加载视频...

视频加载失败

Pro tip: add a Cloudflare WAF rule to block common scanner paths like .env, .git, wp-login they get blocked at the edge and never touch your server

256,686 次观看 • 5 个月前 •via X (Twitter)

77 条评论

Venelin K. 的头像
Venelin K.5 个月前

here's the full list of paths I'm blocking feel free to grab it 👇

Marcus Gill Greenwood 的头像
Marcus Gill Greenwood5 个月前

Better still you can 302 redirect them to these very large files. Script kiddies will really appreciate that

Venelin K. 的头像
Venelin K.5 个月前

haha, this sounds brutal ... the 10GB bin, lol :D

Ilyas 的头像
Ilyas5 个月前

The Managed Rulesets already block most of these requests, and tools like allow you to block the remaining requests

Venelin K. 的头像
Venelin K.5 个月前

nice, didn't know about flarehawk

Tuginho 的头像
Tuginho5 个月前

you can copy and insert this into the expression box: there are some paths related to laravel, ask claude to extend this for your framework if you want

Venelin K. 的头像
Venelin K.5 个月前

nice, this list covers lots of scanners. thanks for sharing!

Kay 的头像
Kay5 个月前

40% is actually really good for early-stage rate limiting. most people don't add any and wonder why their login endpoints get hammered. what are you using, fail2ban or something custom?

Venelin K. 的头像
Venelin K.5 个月前

yeah cloudflare + fail2ban with custom rules

Bartek Igielski 的头像
Bartek Igielski5 个月前

switch it to "matches regex" and use this /(\.php|wp-|[/.]env|\.git|\.vscode|\.idea|\.ds_store|\.ht(access|passwd)|pma|phpmyadmin|config|setup|install|cgi-bin|etc\/passwd|proc\/self|actuator|jolokia|heapdump|\.aws\/|\.ssh\/|xmlrpc)/i less clicking and wider coverage

Venelin K. 的头像
Venelin K.5 个月前

I can't block .php completely... it's a php app :D but good alternative as well, thanks for sharing!

Roman Shalabanov 的头像
Roman Shalabanov5 个月前

@Igloczek Do your URIs actually include .php? I don’t think they do, since your project isn’t built with pure PHP. The routes are clear without .php, so blocking it shouldn’t cause any issues.

Venelin K. 的头像
Venelin K.5 个月前

@Igloczek yeah, you're right but I don't want to block .php just in case, so it may cause some other issues Maybe I can test on a different app, but for production I'm afraid to block them all :D

Trevor I. Lasn 的头像
Trevor I. Lasn5 个月前

this plus auto-ban is the real combo. i ban any IP that triggers 20+ blocked paths per minute. the scanner traffic drops to basically zero

Venelin K. 的头像
Venelin K.5 个月前

yes, I applied the same rules 20+ scans for 1 minute -> fail2ban for 1 day + Cloudflare WAF block it's very effective

Johan Guse 的头像
Johan Guse5 个月前

Hey, it will be very helpful if you could add these texts rules to a gist

Venelin K. 的头像
Venelin K.5 个月前

good idea, here you go

Butch Ewing 的头像
Butch Ewing5 个月前

I also wonder why Cloudflare doesn't do this by default.

Venelin K. 的头像
Venelin K.5 个月前

yeah, it would be very helpful, if you can just toggle this by default :D

David 的头像
David5 个月前

Would just safe a bunch of 404 requests so not that big of a deal imho

Venelin K. 的头像
Venelin K.5 个月前

but still hitting your web server, I don't want this

ethan 的头像
ethan5 个月前

Most of these are setup by default

Venelin K. 的头像
Venelin K.5 个月前

where?

ethan 的头像
ethan5 个月前

Docs

Venelin K. 的头像
Venelin K.5 个月前

sure

Csaba Kissi 的头像
Csaba Kissi5 个月前

I use it on all my sites. It significantly reduces bandwidth usage and makes your site more secure.

Venelin K. 的头像
Venelin K.5 个月前

yeah and also the load on the server. I've added it yesterday and blocks like crazy

Kay 的头像
Kay5 个月前

this plus rate-limiting on login endpoints. cloudflare catches scanner noise but people forget that their /login is hammered just as much. add a turnstile and watch the abuse drop off a cliff

Venelin K. 的头像
Venelin K.5 个月前

yep, already done that and blocks 40% of the login requests.

Agent Mish 的头像
Agent Mish5 个月前

Great tip, straight to the point and useful. Thank you

Venelin K. 的头像
Venelin K.5 个月前

you're welcom, glad it's helpful

DELA 的头像
DELA5 个月前

Can I do this on @BunnyCDN as well?

Venelin K. 的头像
Venelin K.5 个月前

@BunnyCDN I'm not familiar with their UI, but if they have a WAF, yeah you can do it

Mohammad Shoeb 的头像
Mohammad Shoeb5 个月前

Gem!

Venelin K. 的头像
Venelin K.5 个月前

thank you

Avieshek 的头像
Avieshek5 个月前

ELI5?

Venelin K. 的头像
Venelin K.5 个月前

bots always scan your site for files like .env, .git, wp-login etc trying to find vulnerabilities add a cloudflare firewall rule to block these paths and they get stopped at the edge before they ever reach your server make sense now?

Avieshek 的头像
Avieshek5 个月前

Thank you, is this deployable for CloudFlare Zero Trust Firewall Policies or just for site?

Venelin K. 的头像
Venelin K.5 个月前

I've added it to the WAF rules, but maybe it will work with Zero Trust... hadn't test it

Avieshek 的头像
Avieshek5 个月前

WordPress Login as well?

IP 的头像
IP5 个月前

oh, that's cool, thatns for the reminder

Shefali 的头像
Shefali5 个月前

Thanks for sharing, Venelin!

Venelin K. 的头像
Venelin K.5 个月前

welcome, Shefali... hope it's helpful :-)

Aleksandar Janca 的头像
Aleksandar Janca5 个月前

smart will do it tomorrow thanks

Orgest 的头像
Orgest5 个月前

Wow great. Thank you!

Kinder • Grinder 的头像
Kinder • Grinder5 个月前

Thanks, that's great advice.

Venelin K. 的头像
Venelin K.5 个月前

you're welcom, glad it's helpful

Priyanshu.dev 的头像
Priyanshu.dev5 个月前

What if someone doesn't want to use cloudflare and configure these things on their own VPS like Hetzner, Ovhclould or any platform which has no built-in setup. Is there any way to prevent scanning there too like configuration of nginx or what to add these security?

Venelin K. 的头像
Venelin K.5 个月前

yes, fail2ban with custom rules example: 3 of these requests in 1 minute, then ban the IP for 1 day you can configure and adjust

Priyanshu.dev 的头像
Priyanshu.dev5 个月前

Ok, will try 👍

Kim Hudaya 的头像
Kim Hudaya5 个月前

Thank you so much, I got approximately thousands requests like this everyday, crazy that CF by default not blocking them

Venelin K. 的头像
Venelin K.5 个月前

yeah same here, that's why I added these rules

Ganja 的头像
Ganja5 个月前

managed rules already do this, just enable them brah

Venelin K. 的头像
Venelin K.5 个月前

which rule does the same?

Lars LJ 的头像
Lars LJ5 个月前

You blocking core WP paths?

Venelin K. 的头像
Venelin K.5 个月前

yes, because my app is not WP

Lars LJ 的头像
Lars LJ5 个月前

Gotcha 👌

Mo 的头像
Mo5 个月前

Plus Plus captcha or turnstile ✅

Venelin K. 的头像
Venelin K.5 个月前

yep, turstile is mandatory

Qnoox 的头像
Qnoox5 个月前

cloudflare should just add this by default..

Venelin K. 的头像
Venelin K.5 个月前

yes!

Touqeer Shafi 的头像
Touqeer Shafi5 个月前

Is this on the free version or on the paid version?

Venelin K. 的头像
Venelin K.5 个月前

free version... you have 5 rules

Rahul Gupta 的头像
Rahul Gupta5 个月前

thanks for the tip

Venelin K. 的头像
Venelin K.5 个月前

welcome, glad it's helpful

SG 的头像
SG5 个月前

I don't think this is needed. You shouldn't make those public in the first place, not even accidentally.

Venelin K. 的头像
Venelin K.5 个月前

@sanchogodinho why?

SG 的头像
SG5 个月前

If they expose basic stuff like this, they most probably don't know to write secure code. Most big companies don't really use WAF to block these routes.

Venelin K. 的头像
Venelin K.5 个月前

@sanchogodinho haha ok... but I'm not a big company... solo dev here this is helpful and I want to share it, ok? :D

Saïd Aitmbarek 的头像
Saïd Aitmbarek5 个月前

damn cool, i'll copy your gist in CF WAF thanks Ven. :)

Venelin K. 的头像
Venelin K.5 个月前

you're welcome mate, hope it helps!

Liew CheonFong 的头像
Liew CheonFong5 个月前

For non WordPress site

Venelin K. 的头像
Venelin K.5 个月前

yep

Pedro Moranga 的头像
Pedro Moranga5 个月前

Basic tip

Venelin K. 的头像
Venelin K.5 个月前

but it works :D

Ju 的头像
Ju5 个月前

Thanks a lot. My webservers only accept cloudflare reverse proxy requests. This will harden it even more ✊🏼

Venelin K. 的头像
Venelin K.5 个月前

💯

相关视频