Website Security & Threat Management
Thwarting the Tactics of the Equifax Attackers

Thwarting the Tactics of the Equifax Attackers

11/13/2017 · Alex Cruz Farmer

What this post added

This post details specific Remote Code Execution (RCE) vulnerabilities in Apache Struts (CVE-2017-5638, CVE-2017-9805) and explains how Cloudflare's Web Application Firewall (WAF) rules, such as rule 100054 in Cloudflare Specials, protect against these exploits. It also discusses SQL Injection (SQLi) attacks, providing examples of how they work and highlighting the volume of such attacks seen on the Cloudflare network, particularly against WordPress sites. The post emphasizes the role of the WAF in virtual patching these vulnerabilities to protect customers.

Read the original post ↗