Jump to content

Yeah, we've noticed that Cloudflare has been quite.... Proactive in blocking requests that contain certain strings, and we have been looking into how we can fix these issues. 

15" MBP TB

AMD 5800X | Gigabyte Aorus Master | EVGA 2060 KO Ultra | Define 7 || Blade Server: Intel 3570k | GD65 | Corsair C70 | 13TB

Link to post
Share on other sites

13 hours ago, Secondmineboy said:

Why not moving to a different CDN Provider?

 

https://www.incapsula.com/cdn-content-delivery-network/

 

Incapsula has better protection, fully automated DDoS and more features that CF doesnt have.

 

https://www.incapsula.com/incapsula-vs-cloudflare.html

Incapsula is different, but not necessarily better (of course, their own website will tell you differently).

HTTP/2 203

Link to post
Share on other sites

You might just want to disable the keyword filtering in the Web App "Firewall".

Honestly, an attacker would probably just encode his message until it's not captured by the "firewall" and not all requests containing "via gra" or "/var/ www/ html" are necessary evil, you know?

 

EDIT: Seriously, I was blocked for having "via gra" and "/var/ www/ html" without the spaces in my post. So if this "firewall" is meant to fight spam, wow, all it takes are extra spaces. If it is meant to fight file inclusion, great, just encode the fu**ing path differently. The only thing this does is annoy legitimate users. I rate Snakeoil/10.

 

EDIT2: To clarify, I'm solely pissed at the fact that they sell this as a security feature, nothing more. This is not targeted at whomever enabled/activated this feature for this website.

Link to post
Share on other sites

  • 4 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×