Skip to content

Instantly share code, notes, and snippets.

@andcam
Last active June 21, 2023 15:56
Show Gist options
  • Save andcam/921e81d4b6dadfb7fa4ef529b52eecb3 to your computer and use it in GitHub Desktop.
Save andcam/921e81d4b6dadfb7fa4ef529b52eecb3 to your computer and use it in GitHub Desktop.
cloudflare - block common bot paths
(http.request.uri.path contains ".tbz")
or (http.request.uri.path contains ".bz")
or (http.request.uri.path contains ".bz2")
or (http.request.uri.path contains ".gz")
or (http.request.uri.path contains ".tar")
or (http.request.uri.path contains ".7z")
or (http.request.uri.path contains ".xz")
or (http.request.uri.path contains ".tgz")
or (http.request.uri.path contains ".rar")
or (http.request.uri.path contains ".sql")
or (http.request.uri.path contains ".tar")
or (http.request.uri.path contains ".env")
or (http.request.uri.path contains ".bak")
or (http.request.uri.path contains ".old")
or (http.request.uri.path contains ".swp")
or (http.request.uri.path contains ".save")
or (http.request.uri.path contains ".orig")
or (http.request.uri.path contains ".zip")
or (http.request.uri.path contains ".php5")
or (http.request.uri.path contains ".asp")
or (http.request.uri.path contains ".aspx")
or (http.request.uri.path contains ".ashx")
or (http.request.uri.path contains ".nsf")
or (http.request.uri.path contains ".mdb")
or (http.request.uri.path contains ".dat")
or (http.request.uri.path contains ".cgi")
or (http.request.uri.path contains ".pub")
or (http.request.uri.path contains ".key")
or (http.request.uri.path contains ".pem")
or (http.request.uri.path contains ".cfg")
or (http.request.uri.path contains ".jsp")
or (http.request.uri.path contains ".xsd")
or (http.request.uri.path contains ".dat")
or (http.request.uri.path contains ".ini")
or (http.request.uri.path contains ".yml")
or (http.request.uri.path contains ".shtml")
or (http.request.uri.path contains ".ini")
or (http.request.uri.path contains ".log")
or (http.request.uri.path contains ".exp")
or (http.request.uri.path contains ".old")
or (http.request.uri.path contains ".bal")
or (http.request.uri.path contains ".tlz")
or (http.request.uri.path contains ".rej")
or (http.request.uri.path contains ".inc")
or (http.request.uri.path contains ".git")
or (http.request.uri.path contains "/.user.ini")
or (http.request.uri.path contains "/httpdocs/")
or (http.request.uri.path contains "/public_html/")
or (http.request.uri.path contains "/website/")
or (http.request.uri.path contains "/backup")
or (http.request.uri.path contains "/temp/")
or (http.request.uri.path contains "/old-site/")
or (http.request.uri.path contains "/web/")
or (http.request.uri.path contains "/test/")
or (http.request.uri.path contains "/forum/")
or (http.request.uri.path contains "/forums/")
or (http.request.uri.path contains "/portal/")
or (http.request.uri.path contains "/wp1/")
or (http.request.uri.path contains "/wp2/")
or (http.request.uri.path contains "/laravel/")
or (http.request.uri.path contains "/joomla/")
or (http.request.uri.path contains "/phpmyadmin/")
or (http.request.uri.path contains "/phpMyAdmin/")
or (http.request.uri.path contains "/cgi-bin/")
or (http.request.uri.path contains "/administrator/")
or (http.request.uri.path contains "/owa/auth/")
or (http.request.uri.path contains "web.config")
or (http.request.uri.path contains "wp-config.php")
or (http.request.uri.path contains "/autodiscover/autodiscover.xml")
(http.request.uri.path contains "/remmont/")
or (http.request.uri.path contains "/remote/")
or (http.request.uri.path contains "GponForm")
or (http.request.uri.path contains "/dayrui/")
or (http.request.uri.path contains "/e/data/")
or (http.request.uri.path contains "scraper_hashtags")
or (http.request.uri.path contains "/scraper/")
or (http.request.uri.path contains "/adminer/")
or (http.request.uri.path contains "adminer")
or (http.request.uri.path contains "/Admincenter/")
or (http.request.uri.path contains "/plugins/wp-file-upload/")
or (http.request.uri.path contains "/plugins/simple-file-list/")
or (http.request.uri.path contains "/plugins/drag-and-drop")
or (http.request.uri.path contains "/wp-json/wp/v2/users/")
or (http.request.uri.path contains "/wp-info.php")
or (http.request.uri.path contains "/wp-signup.php")
or (http.request.uri.path contains "/wp-backup/")
or (http.request.uri.path contains "/wp-cl-plugin.php")
or (http.request.uri.path contains "/blackhat.php")
or (http.request.uri.path contains "/_.php")
or (http.request.uri.path contains "/1.php")
or (http.request.uri.path contains "/2.php")
or (http.request.uri.path contains "/3.php")
or (http.request.uri.path contains "/4.php")
or (http.request.uri.path contains "/5.php")
or (http.request.uri.path contains "/c.php")
or (http.request.uri.path contains "/wp-m.php")
or (http.request.uri.path contains "/doc.php")
or (http.request.uri.path contains "/content-post.php")
or (http.request.uri.path contains "/eval-stdin.php")
or (http.request.uri.path eq "/admin.php")
or (http.request.uri.path contains "/wp-muen.php")
or (http.request.uri.path contains "/wp-content/themes/wp-update.php")
or (http.request.uri.path contains "/owa/auth/")
or (http.request.uri.path contains "/webfig/")
or (http.request.uri.path contains "/rapi/filedownload")
or (http.request.uri.path contains "/pcidss/report")
or (http.request.uri.path contains "/adminlogin/")
or (http.request.uri.path contains "/admindede888/")
or (http.request.uri.path contains "/houtai/")
or (http.request.uri.path contains "/server/php/")
or (http.request.uri.path contains "/fileupload/server/")
or (http.request.uri.path contains "/uploader/server/")
or (http.request.uri.path contains "tim.php")
or (http.request.uri.path contains "IOptimize.php")
or (http.request.uri.path contains "connector.minimal.php")
or (http.request.uri.path contains "/vendor/phpunit/")
or (http.request.uri.path contains "/1index.php")
or (http.request.uri.path contains "/archives.php")
or (http.request.uri.path contains "/beence.php")
or (http.request.uri.path contains "/defau11.php")
or (http.request.uri.path contains "/defau1t.php")
or (http.request.uri.path contains "/export.php")
or (http.request.uri.path contains "/moduless.php")
or (http.request.uri.path contains "/wp_wrong_datlib.php")
or (http.request.uri.path contains "/wp-content/export.php")
or (http.request.uri.path contains "/wp-content/plugins/wpconfig.bak.php")
or (http.request.uri.path contains "/wp-includes/css/css.php")
or (http.request.uri.path contains "/wp-includes/images/css.php")
or (http.request.uri.path contains "/wp-content/themes/seotheme/")
@andcam
Copy link
Author

andcam commented Jun 21, 2023

(split as there's a character limit on CloudFlare WAF rules)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment