Bot Defense
Swarms, scrapers, and self-inflicted floods against a live SaaS, and the Cloudflare, WAF, and firewall craft that keeps it standing. Every episode is a real attack and what it taught the defenses.
20 posts · ~90 min total reading
-
The bot swarms moved faster than my firewall rules
-
The GoDaddy "No Public API" Myth: Reverse-Engineering the DCC Internal DNS Endpoint
-
The Migration Flip That Took Down a Live Customer (and the Blast Radius I Could Measure in 12 Seconds)
-
Cloudflare Error 1014: The Cert Issued. The Page Didn't Load.
-
The Cloudflare-for-SaaS + IIS Gotcha Nobody Documents: SNI vs Host Header
-
Cloudflare Pro is a box of levers, not a managed service
-
Geo-blocking everywhere except the US and Canada, and the one clause that saves your SEO
-
The Prod Box Was DDoSing Itself: An iCal Calendar Feature Looping Through the Public Edge
-
"The Whole Island Can't Reach Your Site": US Territories Are Separate Countries to Cloudflare
-
Five firewall rules beat the proxy swarm, but the real bug was my blind spot
-
Whack-a-mole is a real strategy: firewall blocks as a legitimate holding pattern
-
Your IIS Logs Start Lying the Moment Cloudflare Goes Live
-
JS Detections: the one Pro-tier Cloudflare lever that actually catches HTTP-replay proxies
-
Bot Swarm Detection: The Three-Signal Triangle That Catches What IP Reputation Misses
-
The method outlasts the patch
-
The fastest fix was blocking the bot by name
-
The decorative database: when your blocklist table isn't actually on the request path
-
The UA blocklist is the right-sized fix for an identified crawler (and the wrong one for a swarm)
-
The attacker was our own redirect logic
-
The rate-limiter that banned our power users: 302 to 200 redirects look like an attack