DDOS update recently

What is the name of the domain?

What is the error message?

Sorry, you have been blocked. You are unable to access secure-exchanges.com

What is the issue you’re encountering

User is receiving a block message when uploading files. The message says “Sorry, you have been blocked.”

What steps have you taken to resolve the issue?

I believe the issue was triggered by high-frequency chunked file uploads. I created an exclusion rule in the WAF for our IP address and upload endpoint, and the problem appears to be resolved for now.

Was the site working with SSL prior to adding it to Cloudflare?

Yes

What is the current SSL/TLS setting?

Full

What are the steps to reproduce the issue?

We upload and download files using chunked requests. In some cases, the same URL is called over 1,000 times in a short period.

The issue began suddenly without any configuration changes on our end. Users attempting to upload files started receiving block messages. We’ve been using Cloudflare for almost 6 months without problems until now.

Screenshot of the error

Check your security event log for the reason the requests were challenged or blocked and then you can configure your rules and settings as needed…
https://dash.cloudflare.com/?to=/:account/:zone/security/events

Thanks, the Events tab helped us identify the issue.

I’m just surprised that the block only started triggering recently.

Cloudflare will always be adjusting the protections based on threats and what they see (and won’t give details for obvious reasons). Sometimes this may trigger against things that made it through before. It’s a fine line to walk.

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.