Hacker Newsnew | past | comments | ask | show | jobs | submit | ferat's commentslogin

Today, after the Cloudflare outage, I noticed that almost all upload routes for my applications were being blocked.

After some investigation, I realized that none of these routes passed through Cloudflare OWASP. The reported anomalies total 50, exceeding the pre-configured maximum of 40 (Medium).

Despite being simple image or video uploads, the WAF is generating anomalies that make no sense, such as the following:

Cloudflare OWASP Core Ruleset Score (+5)

933100: PHP Injection Attack: PHP Open Tag Found

Cloudflare OWASP Core Ruleset Score (+5)

933180: PHP Injection Attack: Variable Function Call Found

For now, I’ve had to raise the OWASP Anomaly Score Threshold to 60 and enable the JS Challenge, but I believe something is wrong with the WAF after today’s outage.

This issue was still not solved to this moment.


It's really interesting that you don't need to upload the file to a server to convert. Did you write the converter entirely from scratch?


I'm using a JavaScript library called LameJS, and web workers to speed up the file conversion


For truly free processing local is the only sensible option.


Thank you very much for your words. I can't even imagine the lack of time with 3 children, this is my first and I'm already going crazy, haha


Enjoy it and spend as much time in the moment as you can.

It doesn’t seem like it now, but I promise you, the kid will be an adult in the blink of an eye.

People also told me this but I didn’t grasp it at the time.


A simple, FREE, personal solution for creating and customizing surveys directly in your browser. There is no need for an account or backend storage. Gather valuable insights effortlessly and securely. Connect surveys to Google Sheets or custom backend.


Two years ago I made https://vemto.app, a GUI code generation tool for PHP/Laravel developers. At the time, my wife and I were going through a difficult process, in which we urgently needed to move out of an apartment. The tool sold well enough for us to put a down payment on a house, and has continued to sell for those two years, and now I'm working on a second, more powerful version that not only generates code, but can connect to existing projects to edit them. There is a video of the second version at this link: https://twitter.com/Tiago_Ferat/status/1591450807433826304


Yes... it is for Windows, macOS and Linux


Sorry, but I don't understand what you mean by "Zero-Info generic landing page". Did you try scrolling the landing page to read it?

About the comments, I believe some of the software users decided to comment. Only that.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: