Website Security & Threat Management
Keeping Drupal sites safe with Cloudflare's WAF

Keeping Drupal sites safe with Cloudflare's WAF

4/20/2018 · Maitane Zotes

What this post added

This post details the implementation and effectiveness of a specific WAF rule (D0003) deployed to mitigate the Drupalgeddon 2 vulnerability (CVE-2018-7600). It analyzes attack patterns, including POST requests targeting the 'mail' and 'name' fields, and provides code snippets of malicious payloads. The post quantifies the rule's success by reporting over 500,000 blocked attacks in the first week and over 56,000 per day subsequently, highlighting the WAF's role in protecting against critical remote code execution exploits.

Read the original post ↗