跳到主内容
@wquguru
精选75Cloudflare WAF(Changelog)云与平台

Cloudflare WAF 2026-09-01:新增 WHERE+WITH SQLi 检测并改为拦截

WAF - WAF Release - 2026-09-01

原文
发到 X
推荐理由

WAF 策略从 Log 变更为 Block 属于破坏性变更,可能直接阻断合法业务流量。请受影响用户立即在防火墙模式下测试该规则,确认无误后再切换至拦截模式。

This release introduces a new threat detection to enhance protection against SQL injection (SQLi) attempts exploiting complex query syntax.

本次发布引入了新的威胁检测功能,以增强对利用复杂查询语法进行 SQL 注入(SQLi)攻击的防护。

Key Findings

主要发现

  • SQLi Protection: Improved coverage for SQL injection patterns involving WHERE comparisons combined with WITH clauses.
  • SQLi 防护:改进了对涉及 WHERE 比较与 WITH 子句组合的 SQL 注入模式的覆盖范围。
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...bcfa0966N/ASQLi - WHERE Comparison With WITH ClauseLogBlockThis is a new detection.
规则集规则 ID旧版规则 ID描述先前操作新操作备注
Cloudflare 托管规则集...bcfa0966不适用SQLi - 带有 WITH 子句的 WHERE 比较记录日志阻止这是新增的检测项。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近