We have Simulated Below attack last and below are the observations.
Types Of attack Simulated
SQLi - Equation
HTML / Cross Site Scripting
Password Brute Force
DOS attack
Tools Used -
Burp Suite
Kali Linux
Result of Attck Simulation
SQLi - Equation → Successful
HTML / Cross Site Scripting → Not detected
Password Brute Force → Not Detected at Security Alert More than 1k
DOS attack → Not Detecting IP Traffic
We have Simulated the attack on the application which onboarded over Cloudflare
it’s CNAME Setup below are the observations.
Types Of attacks Simulated on Cloudflare onborded applications.
SQLi - Equation
HTML / Cross-Site Scripting
Password Brute Force
DDOS attack
Syn Flood
Ping flooding
Tools Used -
Burp Suite
Kali Linux
Results of Attack Simulation
SQLi - Equation → successfully detected.
HTML / Cross-Site Scripting → Not Blocked by Cloudflare WAF.
Password Brute Force → Not Blocked by Cloudflare WAF.
DOS attack → Not Blocked by Cloudflare WAF
Syn Flood → Not Blocked by Cloudflare WAF
Ping flooding→Not Blocked by Cloudflare WAF