/plushcap/analysis/cloudflare/shellshock-protection-enabled-for-all-customers

Shellshock protection enabled for all customers

What's this blog post about?

On September 29, 2014, CloudFlare introduced automatic protection against the Shellshock bash vulnerability for all its paying customers through their WAF (Web Application Firewall). Following this, they received requests to extend this protection to all customers, including those on the Free plan. After assessing the actual Shellshock traffic and understanding the severity of the issue, CloudFlare developed a Basic ShellShock Protection that is now operational for every customer, regardless of their plan (Free, Pro, Business, or Enterprise). Paying customers still benefit from more complex Shellshock rules in the WAF. This ensures that all CloudFlare users are protected from common attack vectors related to Shellshock, while paying customers enjoy additional advanced protection.

Company
Cloudflare

Date published
Sept. 29, 2014

Author(s)
John Graham-Cumming

Word count
152

Language
English

Hacker News points
None found.


By Matt Makai. 2021-2024.