3 ms·
This is just an invalid path on the server, unless your server is bad and needs to be fixed. What's the issue?
by andersa 3y ago
This is just an invalid path on the server, unless your server is bad and needs to be fixed. What's the issue?
- waihtis 3y agoif this is executed by the backend, that means something more nefarious could be executed too
- slig 3y agoThis is being passed as the `HOST` header, not the path.
- eli 3y agook? If that causes a problem for your server then your server is broken.
- slig 3y agoDjango raises an `Invalid HTTP_HOST header`, it's not causing an error, I meant that it's obvious wrong and that CF WAF should catch that before reaching the origin server.
- eli 3y agoOh, I mean the default settings are to let most requests through and block ones that meet some threshold for bad. You can tweak the settings or add your own rules though. You can easily configure CF's WAF to block Host headers with invalid characters. I personally wouldn't bother. I wouldn't read too much into the defaults. I'm sure they're aiming for a sweet spot between blocking likely attacks and generating too many support tickets from crappy apps that rely on some non-spec behavior. It's not meant to be proof a request is well formed.