Website Security & Threat Management
Protect Your Sites With Rapidly Deployed WAF Rules

Protect Your Sites With Rapidly Deployed WAF Rules

1/21/2014 · John Graham-Cumming

What this post added

This post details the deployment of a new global Web Application Firewall (WAF) that supports common rule sets (like OWASP) and a custom rule language. It provides examples of how Cloudflare engineers use this custom rule language to protect specific customers from botnets and zero-day exploits by writing and deploying rules in under 30 seconds. Examples include blocking WordPress number bots, Anonymous attack messages, and POST requests to non-existent URLs. It also mentions patching a WHMCS zero-day exploit and deploying rules for Plone and PHP remote code execution vulnerabilities.

Read the original post ↗