Help hacker is bypassing my ip rules and my waf tools rules how to block it?

What is the name of the domain?

private

What is the issue you’re encountering

help hacker is bypassing my ip rules and my waf tools rules how to block it? i added waf and tool ban on asn and still bypassing

What steps have you taken to resolve the issue?

help hacker is bypassing my ip rules and my waf tools rules how to block it?
i added waf and tool ban on asn and still bypassing

What are the steps to reproduce the issue?

help hacker is bypassing my ip rules and my waf tools rules how to block it?
i added waf and tool ban on asn and still bypassing

Screenshot of the error

You’re filtering on Mitigated, so it sounds like those were blocked. What makes you think they’re bypassing your rules? Are these requests getting to your server?

3 Likes

not it is not mitigated, instead of blocking it is doing a challenge and as you can see the script kiddie is bypassing my waf rules it means the script is able of doing superbot verification per second and scan , as you can see in the image

i need to block it and i dont know how because it is bypassing cloudflare. help cloudflare bug is found @cloudflare

I’m not seeing that. I see a list of requests that were mitigated. When I check my mitigated requests by expanding an entry, I see they’re all 403s. I have that same IP address attacking mine, and my Custom Rule that blocks that ASN is blocking them:

I even searched my server logs for that IP, and it never appears.

You’re going to have to provide better evidence than this if you’re claiming there’s a bug.

If you’re thinking they’re bypassing your rules and hitting Super Bot Fight Mode, this behavior indicates that SBFM is triggering first. Try turning it off, then monitor activity.

Also, is this a Free plan zone, or Paid?

2 Likes

oh then im quiet, looks like we discovered a botned using microsoft networks hehe

its free( im poor) glad to know its mitigated, im doing hosting testing and its relevant to me to maintain everything working perfectly

i reported the ip, you can report it here too (if you want to contribute) Microsoft security reporting portal

2 Likes

found out a hacker is not getting blocked by the waf , and despite exclusivelly blocking asn in ip custom waf and waf tools, the hacker still bypass and doesnt get blocked. it gets bot mode but i need it to block it , and despite… " idem" it stills happening. so its like a bug.

What makes you think they’re not hitting bot fight mode first and getting challenged there?

https://developers.cloudflare.com/bots/get-started/free/#limitations

And please answer my earlier question: Are these requests getting to your server?

2 Likes

they are bypassing waf, i literally have a rule that deny everything except 1 carrier asn, and they are bypassing everything they appear in "mitigated = no "

help i need to get rid of those hackers

You need to disable “Bot fight mode”. After that your WAF rules will work, blocking traffic correctly. “Bot fight mode” from the Cloudflare Free plan is useless.