Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


LET is down? - Page 6
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

LET is down?

12346»

Comments

  • @LEBAdmin said:

    The CF rules are being eased off as the attacks have not returned for 24 hours.

    This week is Cloudflare innovation security week check on Friday's announcement on their blog will be opening up access to their Enterprise Bot Management product to other tier plans. Trust me when I say Bot Management support in Cloudflare Firewall will stop dead most layer 7 application level attacks that you configure their Firewall for :smile:

    Thanked by 1TimboJones
  • I am still getting CF 5 sec. The DDoS is still effective?

  • NeoonNeoon Community Contributor, Veteran

    @eva2000 said:

    @LEBAdmin said:

    The CF rules are being eased off as the attacks have not returned for 24 hours.

    This week is Cloudflare innovation security week check on Friday's announcement on their blog will be opening up access to their Enterprise Bot Management product to other tier plans. Trust me when I say Bot Management support in Cloudflare Firewall will stop dead most layer 7 application level attacks that you configure their Firewall for :smile:

    Sounds like marketing bla bla, I don't think they ever will be able to, stop bot attacks before it renders the entire application useless for users.

    Thanked by 1skorupion
  • eva2000eva2000 Veteran
    edited March 2021

    @Neoon said: Sounds like marketing bla bla, I don't think they ever will be able to, stop bot attacks before it renders the entire application useless for users.

    It will definitely help more than what's currently available now. Just 1-2 days more to find out.

  • I hate waiting on Cloudflare.

    Thanked by 1yoursunny
  • skorupionskorupion Member, Host Rep

    They probably bought like at least a month of DDoS for like 60 bucks

  • @eva2000 said: It will definitely help more than what's currently available now. Just 1-2 days more to find out.

    I know you're a Cloudflare MVP and like to talk about them in a positive light, but the truth is that most ad blockers and some antiviruses already block the /cdn-cgi/bm/ script.

    Some bot management products perform the check before allowing access (something like IUAM, but replace the IUAM check with bot management), now if something was planned along those lines that would be helpful.

  • eva2000eva2000 Veteran
    edited March 2021

    @stevewatson301 said: I know you're a Cloudflare MVP and like to talk about them in a positive light, but the truth is that most ad blockers and some antiviruses already block the /cdn-cgi/bm/ script.

    Bot Management helps more for automated bots which probably won't have ad blockers and well Bot Management source data isn't just from the javascript. There's also additional javascript detection but that is additional to Bot Management and not enabled by default on Enterprise plans only non-Enterprise https://developers.cloudflare.com/bots/about/javascript-detections.

    Enable JavaScript detections
    For Free customers (Bot Fight Mode), JavaScript detections are automatically enabled and cannot be disabled.

    For all other customers (Super Bot Fight Mode and Bot Management for Enterprise), JavaScript detections are optional. To adjust your settings, go to Firewall > Bots.

    For more details on how to set up bot protection, see Get started.

    Bot Management operates via CF Firewall so you can block/challenge the bot before the request is made.

    This is just from one of my sites for past week and this is a fairly quiet week bot wise and I don't even have optional Javascript bot detection enabled.

    data sources as per https://developers.cloudflare.com/bots/about/plans/bm-subscription

    Machine Learning is a big one

    Machine learning
    The Machine Learning (ML) engine accounts for the majority of all detections, human and bot. This approach leverages our global network, which proxies billions of requests daily, to identify both automated and human traffic. We constantly train the ML engine to become more accurate and adapt to new threats. Most importantly, this engine learns from traffic across all Cloudflare domains and uses these insights to score traffic while honoring our strict privacy standards.

    The ML engine produces scores 2 through 99.

  • eva2000eva2000 Veteran
    edited March 2021

    Not entirely the same as Bot Management, but CF announced Super Bot Fight Mode https://blog.cloudflare.com/super-bot-fight-mode/. Difference is Enterprise Bot Management deeply integrates with CF Firewall rules so you can do custom rules targeting specific bot scores/patterns. While Super Bot Fight Mode doesn't have that deeper integration and just has settings to group automated, likely automated and verified bot actions.

Sign In or Register to comment.