Hi. On a vBulletin forum I made a post and it seemed to have tripped their CloudFlare WAF. I don’t use the CloudFlare WAF on my end so I can’t confirm this by virtue of a log file. But I narrowed down the possible issue that tripped the WAF with this text: “select disk #.”

Yes, that text included the quotes in my post submission on the forum. I’m thinking the WAF is thinking this text is some form of null byte? Anyone have a guess as to why this specific text would trip the WAF?


Maybe it thinks it’s command injection since that can be interpreted as a diskutil command. Maybe the vbulletin admin has extra WAF rules turned on that cause this.

