Cloudflare OWASP firewall rules seem to break TD Composer

Posted in: Newspaper
Post count: 44

I noticed I was having problems trying to import some new cloud templates. They would import but couldn’t save – spinning icon forever… I checked all my config/parameters/plugins and still busted.

Logged into Cloudflare and went to firewall rules and I see that the OWASP rule set is blocking these requests.

981176 Inbound Anomaly Score Exceeded (Total Score: 84, SQLi=12, XSS=35): Last Matched Message: IE XSS Filters – Attack Detected. OWASP Inbound Blocking Filter
960024 Meta-Character Anomaly Detection Alert – Repetative Non-Word Characters OWASP Generic Attacks Filter
973306 XSS Attack Detected OWASP XSS Attacks Filter
973332 IE XSS Filters – Attack Detected. OWASP XSS Attacks Filter
973333 IE XSS Filters – Attack Detected. OWASP XSS Attacks Filter
973334 IE XSS Filters – Attack Detected. OWASP XSS Attacks Filter
973335 IE XSS Filters – Attack Detected. OWASP XSS Attacks Filter
973338 XSS Filter – Category 3: Javascript URI Vector OWASP XSS Attacks Filter
973344 IE XSS Filters – Attack Detected. OWASP XSS Attacks Filter
981133 Prequalify PM OWASP Generic Attacks Filter

I’d like to leave these firewall rules engaged. For now, I guess I’m going to whitelist my static IP as being trusted. Is there any way that in the future the tdcomposer/editor could be updated so it won’t trigger these? I imagine as hosting matures and more people implement firewalls/wafs this will only compound.

Post count: 20688

Hi,

I could add this topic on our list for testing. Our developer team will take a look when time permits. Thank you for mentioning it.

Post count: 44

Thanks! To reproduce just enable OWASP recommended rules for WordPress sites in cloudflare and try to edit a template. In developer mode you will see 404 on some api calls that get flagged with those XSS attack filters. Whitelist your IP in the firewall rules editor and all is well again.

Viewing 3 posts - 1 through 3 (of 3 total)
The forum ‘Newspaper’ is closed to new topics and replies.