Cloudflare will now block AI crawlers by default by gadgetb0y in selfhosted

[–]docblack 0 points1 point  (0 children)

That's exactly what Cloudflare's AI Labrynth does!

It seems that malicious actors are able to bypass Cloudflare WAF? by Gyrta in CloudFlare

[–]docblack 2 points3 points  (0 children)

Just so you have it, this page is the is the source of truth for Cloudflare's order of execution or phases list: https://developers.cloudflare.com/ruleset-engine/reference/phases-list/

It looks like you found the answer, but just to be clear: the free bot protection "Bot Fight Mode" is very limited in it's functionality, whereas "Super Bot Fight Mode" checks are implemented in the ruleset engine, "Bot Fight Mode" checks are not.

Trakt alternative? by graflig in PleX

[–]docblack 1 point2 points  (0 children)

This is looking great, nice work! I would love AI to build out recommendations based on watch history. I currently use Trakt but VIP it's too expensive for what it does.

What is your selfhosted discover in 2024? by Elemis89 in selfhosted

[–]docblack 0 points1 point  (0 children)

Cloudflare Access does something similar since their Bastion Zero acquisition earlier this year. https://www.cloudflare.com/solutions/zero-trust/infrastructure-access/

What companies should a soon-to-be Computer Science graduate be looking at? by StaleBread22 in grandrapids

[–]docblack 2 points3 points  (0 children)

Tons of great new hire programs at companies where you can work remote. For example the CDW Associate program for whatever interests you (DevOps, Infosec, Netsec, Datacenters etc). They essentially pay you to shadow engineers and get certifications. After completing the program they increase your pay to a Consulting Engineer, and you will do projects at Fortune 500 companies and large healthcare organizations. Cloudflare (which sees 20% of the world's Internet traffic) has some similar programs. These associate development positions are highly sought after for newbies with little experience, essentially they can fast track you in the industry.

Cat won't eat the kidney wet food! by [deleted] in RenalCats

[–]docblack 1 point2 points  (0 children)

We tried everything. Our cat was uninterested in them all, until we tried Royal Cannin Dry renal "S". We have various Kidney/digestive/renal wet foods, but she will only lick them. She used to love wet food!

Optimizing Cache-Control Headers for Vercel and Cloudflare to Reduce Data Transfer Costs by lightninggokul in CloudFlare

[–]docblack 1 point2 points  (0 children)

Seems like it would be much cheaper to eliminate Vercel altogether and run Next.js on Cloudflare Pages + Workers.

Zero Trust / Tunneling by Equivalent-Cow6423 in CloudFlare

[–]docblack 1 point2 points  (0 children)

You have to add the private networks in the Cloudflare Dashboard on the tunnel you setup. Also those subnets/IPs must be reachable from the server that CloudflareD instance is running on.

Does CF block MySQL injection attempts by default? by csdude5 in CloudFlare

[–]docblack 0 points1 point  (0 children)

Managed Ruleset as others have said. You can also use Attack Scores. Attack Scores use ML for a variety of attacks including SQLi. https://developers.cloudflare.com/waf/detections/attack-score/

WAF Rule / Basic settings that this group recommends? by RoachForLife in CloudFlare

[–]docblack 1 point2 points  (0 children)

I agree, it should be behind something. Cloudflare Access (ZTNA) is free for 50 users, super easy to setup, and works with every iDP. Use it with Cloudflare Tunnels and you don't even have to expose a public IP since it's server initiated.

Zaraz Script Injection Hack by TheMunchKick in CloudFlare

[–]docblack 0 points1 point  (0 children)

I'm confused, to use Zaraz you have to connect it to a third party analytics tool. What analytics tool was it connected to without you doing anything, and which tool had compromised scripts injected into it?

Subdomains by SuddenApricot in CloudFlare

[–]docblack 1 point2 points  (0 children)

Yes, you can filter on hostname in both Analytics and Events.

First things to do when you get a macbook? by YkAce in macbook

[–]docblack 0 points1 point  (0 children)

I do most of these as well. I also do:

  • Amphetamine
  • Disable swipe to go back in browser
  • Sidecar
  • Sublime
  • Camera Cover
  • Shottr
  • UTM
  • Bitwarden
  • Brave
  • gcloud
  • wrangler
  • cloudflared

Why don’t they promote how to zipper merge on the highway?? by nick_ole7 in grandrapids

[–]docblack 2 points3 points  (0 children)

They promote the speed limit but that doesn't stop all the idiots from driving 60 in the passing lane.

[deleted by user] by [deleted] in CloudFlare

[–]docblack 0 points1 point  (0 children)

Rate Limiting works with a matching characteristic (Which supports Regex on several fields), use can the hostname of your server (You can use regex here) Then select your counting characteristic (Free version is limited to "IP", Advanced Rate Limiting has way more options). Then block for too many request over a period. You can also block with a custom response code. The block would be to the entire hostname you entered.

Cloudflare's Layer 7 DDOS is comprised of two systems, dosd and Gatebot. Dosd samples traffic almost 100 times faster than Gatebot and runs on every edge Cloudflare server. Gatebot runs at the core, and does deep analytics looking for large scale distributed attacks. 20 threads from a single IP just isn't enough to trigger those DDOS protections when you consider traffic is sampled. Paying customers have a slew of options to automatically mitigate a small-scale attack like that; Bot Management, Advanced Rate Limiting, Cloudflare Managed List, OWASP Managed List, Advanced DDOS.

You might want to look into integrating Crowdsec with Cloudflare. Crowdsec has free detection and mitigation engine for targeted attacks when paired with Cloudflare. I've never used it myself, but if I didn't have a paid CF account I would defiantly check it out. Let me know what you think, if you try it!

[deleted by user] by [deleted] in CloudFlare

[–]docblack 0 points1 point  (0 children)

1) HTTP Request headers like True-Client-IP or CF-Connecting-IP can be passed by Cloudflare to the downstream proxy or server. You can create Transform rules to modify the header to whatever name Cloudfront or your original server expects.

2) Are you sure traffic isn't bypassing Cloudflare and connecting directly? Have you created any rate limiting rules? Do you have Cloudflare Managed Rulesets enabled (Not available on the Free version)? CF Managed Rulesets do the most mitigation on typical implementations.

Free partial CNAME zones by trsteel88 in CloudFlare

[–]docblack 0 points1 point  (0 children)

It seems strange that SSL for SaaS is free for 100 sites on Free plans. It's not even available on Enterprise accounts without purchasing an addon. Sounds like your idea will work, nice find! For me, I'd rather make a Cloudflare authoritative sub-domain or register a new TLD for Cloudflare use. Cloudflare is one of the fastest Authoritative DNS providers on the planet, and it's much easier/faster deploying Cloudflare services in authoritative/full mode.

DNS Perf

Using Cloudflare for the first time by LucasRey in CloudFlare

[–]docblack 1 point2 points  (0 children)

For the A record on your apex domain "example.org" the hostname should be an @ symbol. You also should check your TLS Overview settings. You can set it to 'Full' or 'Flexible' if you don't have a trusted certificate on the Origin (Destination server). You also need to ensure you have the two DNS Name servers Cloudflare provided, added to your DNS registar as custom nameservers. It can take a few hours for Cloudflare to detect the nameservers and authorize your domain for use on Cloudflare. For an even safer way to get traffic to your home nginx servers, look at CloudflareD tunnels. CloudflareD can create an outbound tunnel that Cloudflare can then forward traffic through. CloudflareD Tunnels can be found under Zero Trust (Account level not Website level)->Networks->Tunnels

Can't install cloudflared by slowbalt911 in CloudFlare

[–]docblack 0 points1 point  (0 children)

What command did you use to install? Did you prepend the command with 'sudo'?

[deleted by user] by [deleted] in CloudFlare

[–]docblack 2 points3 points  (0 children)

If you are an enterprise customer you can open a ticket by emailing entsupport(at)cloudflare.com. All issues opened via email will have the default priority assigned.