toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

211
active users

#waf

2 posts2 participants0 posts today

Do you need an out-of-band and proactive WAF that actually keeps up?

Time to start using the CrowdSec WAF! It’s lightweight, open source, and 100% free.

Best of all, it…
✨ Scales with your infrastructure
✨ Imports your existing ModSecurity rules
✨ Fits right into automation & CI/CD pipelines

Discover how CrowdSec WAF can upgrade your web app security ➡️ crowdsec.net/blog/crowdsec-waf

crowdsec.netCrowdSec WAF: The Collaborative Future of Web Application SecurityProtect your apps with a modern, open-source WAF that adapts in real time using behavior-driven detection and global threat intelligence.
Replied in thread

@drscriptt Naive question: WHEN does the average #Internet #user ever open up a webpage with an #IP address instead of a #domain or even #FQDN?

  • Seriously, the only cases I saw were either some old, non-public - facing server in some B2B/API setting or a test that #httpd / #ngnix / #ssh / … function properly on like a #VPS and that the #DNS hasn't been updated (yet!) to include said host / FQDN in the records, and even then it's bad cuz you'd rather want to use it's FQDN instead because with #IPv4 shortages on one hand and tools like #Portainer on the other, one should not use an #IPaddress as addressing method because #WAF / #Proxies used to "#MUX" / "#NAT" services under one IP address or #IPv6 block may need that distinction by being queried for a specific FQDN...

The Idea if !SSL / #TLD for #IPaddresses makes me feel like Jeff Goldblum!

Replied in thread

@lukeshu So I guess #Anubis has an explicit exception to handle #Lynx and will instead rely on rate-limits and other static means to detect #scrapers and handle with #UserAgent #abuse cases, like #fail2ban-style autobanning of violating IPs...

  • This makes sense for a #WAF like Anubis and would've been the only viable option I'm aware of.

I wounder if anyone has tried using Anubis on @torproject / #Tor to protect #OnionService|s since that would be a reasonable application for it as well.

Replied in thread

@Wheels @RickiTarr

That will be the next step for this administration, after ignoring judicial orders, it will ignore congress, and there will be no consequences.

This is a prediction.

Also, is this correct? > Congress formally controls the budget, but the administration manages the money. Once the administration has the money, if they refuse to spend per congressional budget, there is only the judiciary (ignoring), and congress (1. Controls, 2. predicted to ignore), to enforce?
#WAF

Replied in thread

@LibreKitsune I still consider this a hostile act and a blatant violation of their previous #settlement that forced them into #publishing said #IPv4 #ranges...

  • In fact had they not actively worked against that previously and it only raised my attention when I saw errors re: said ranges.

I'm considering to build a #workaround on #GitHub to just use a #cookie and some #compute to do it, but if I had cash to spare I'd sue them into removing #ClownFlare and allowing me to scrape the list directly...

  • I'm very close to just sending them an #invoice for the personnel hours wasted on that bs and billing them regularly for the expense of manually checking the difference between those (@ minimum of 60:15 billable minutes)...

Otherwise I do expect regulators to actually go after #OpenAI and force them to undo the #Cloudflare-based #Enshittification, since it's neither feasible nor reasonable to claim "#DDoS-#Protection" for a 48 Bytes (!!!) file...

  • Every #WAF / #WebApplicationFirewall I know would not get triggered even if I were to query it once per hour (which I now do just to annoy them or rather ClownFlare!...

👉 URLs meant for bots should not use Cloudflare’s bot blocker. 👈

If your website uses Cloudflare, you should set an appropriate security level for RSS feeds and APIs by using Page Rules. 🤌

This timeless clusterfuck has been unearthed by the Open RSS project and is getting some attention.🤞

openrss.org/blog/using-cloudfl
news.ycombinator.com/item?id=4

openrss.orgUsing Cloudflare on your website could be blocking RSS usersCloudflare's security features could be blocking RSS feed users from accessing your website