跳到主内容
@wquguru
精选75Cloudflare WAF(Changelog)云与平台

Cloudflare WAF 泄露凭据检测新增扫描 Authorization 头

WAF - Leaked credentials detection now scans Authorization headers

原文
发到 X

Leaked credentials detection now scans the Authorization request header for Basic Authentication credentials. Previously, the detection only inspected request bodies, query strings, and headers for well-known web applications or custom detection locations, which meant credentials sent through HTTP Basic Authentication were not covered by default.

泄露凭据检测现在会扫描Authorization请求头中的基本认证凭据。此前,检测仅检查请求体、查询字符串以及针对知名Web应用或自定义检测位置的头部,这意味着通过HTTP基本认证发送的凭据默认情况下不会被覆盖。

This new default scan location decodes the Authorization: Basic <credentials> header and compares the extracted username and password against Cloudflare's database of leaked credentials, the same way as other default scan locations. Matches populate the existing leaked credentials fields, such as cf.waf.credential_check.password_leaked, and trigger the Exposed-Credential-Check managed transform header if configured, so you can reuse existing custom rules and rate limiting rules without changes.

这个新的默认扫描位置会解码Authorization: Basic <credentials>头部,并将提取的用户名和密码与Cloudflare的泄露凭据数据库进行比较,方式与其他默认扫描位置相同。匹配结果会填充现有的泄露凭据字段,如cf.waf.credential_check.password_leaked,并在配置时触发Exposed-Credential-Check托管转换头部,因此您可以重用现有的自定义规则和速率限制规则,无需更改。

This change was applied automatically for zones with leaked credentials detection enabled. No configuration changes are required.

此更改已自动应用于启用了泄露凭据检测的区域。无需进行任何配置更改。

For more information, refer to Leaked credentials detection.

更多信息,请参阅泄露凭据检测。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近