WAF Feature: Please add option to block empty user-agent request
-
For the past few months been hit by a malware on cPnael based hosting. WF doesn’t remove the malware completely, with some malware files remain deep in folders which the malware then hits with http requests with empty user-agent. If the file is found it gets executed and malware is back.
I’ve narrowed down lots of ways this malware is getting into my websites, one of them is this hunting with empty user-agent requests, and hundreds of them. WF does have limit for 404 blocking, but the malware first tries with http1.1, which gives 301, then tries with http2.0 which gives 404. So WF doesn’t block this offending IP.
Kindly update the WAF to tackle these kind of malware installations.
PS, I’m now moving my websites to host which gives each website separate user, so if one website gets infected, it doesn’t spread to other websites like in single user cPanel hosting.
- You must be logged in to reply to this topic.