Attack Simulation

Hello Team,

We have Simulated Below attack last and below are the observations.

Types Of attack Simulated
SQLi - Equation
HTML / Cross Site Scripting
Password Brute Force
DOS attack

Tools Used -
Burp Suite
Kali Linux

Result of Attck Simulation
SQLi - Equation → Successful
HTML / Cross Site Scripting → Not detected
Password Brute Force → Not Detected at Security Alert More than 1k
DOS attack → Not Detecting IP Traffic

What is your question?

We have Simulated the attack on the application which onboarded over Cloudflare
it’s CNAME Setup below are the observations.

Types Of attacks Simulated on Cloudflare onborded applications.
SQLi - Equation
HTML / Cross-Site Scripting
Password Brute Force
DDOS attack
Syn Flood
Ping flooding

Tools Used -
Burp Suite
Kali Linux

Results of Attack Simulation
SQLi - Equation → successfully detected.
HTML / Cross-Site Scripting → Not Blocked by Cloudflare WAF.
Password Brute Force → Not Blocked by Cloudflare WAF.
DOS attack → Not Blocked by Cloudflare WAF
Syn Flood → Not Blocked by Cloudflare WAF
Ping flooding→Not Blocked by Cloudflare WAF

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.