精选75Cloudflare WAF(Changelog)云与平台
Cloudflare WAF 2026-09-01:新增 WHERE+WITH SQLi 检测并改为拦截
WAF - WAF Release - 2026-09-01
推荐理由
WAF 策略从 Log 变更为 Block 属于破坏性变更,可能直接阻断合法业务流量。请受影响用户立即在防火墙模式下测试该规则,确认无误后再切换至拦截模式。
This release introduces a new threat detection to enhance protection against SQL injection (SQLi) attempts exploiting complex query syntax.
本次发布引入了新的威胁检测功能,以增强对利用复杂查询语法进行 SQL 注入(SQLi)攻击的防护。
Key Findings
主要发现
- SQLi Protection: Improved coverage for SQL injection patterns involving WHERE comparisons combined with WITH clauses.
- SQLi 防护:改进了对涉及 WHERE 比较与 WITH 子句组合的 SQL 注入模式的覆盖范围。
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | ...bcfa0966 | N/A | SQLi - WHERE Comparison With WITH Clause | Log | Block | This is a new detection. |
| 规则集 | 规则 ID | 旧版规则 ID | 描述 | 先前操作 | 新操作 | 备注 |
|---|---|---|---|---|---|---|
| Cloudflare 托管规则集 | ...bcfa0966 | 不适用 | SQLi - 带有 WITH 子句的 WHERE 比较 | 记录日志 | 阻止 | 这是新增的检测项。 |
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力