Search code examples
wordpresssecuritycloudflareweb-application-firewall

What are the potential risks of not using a Web Application Firewall?


I develop and manage a small promotional/marketing website on Wordpress for a startup SaaS product. We're using Cloudflare for DNS and whatnot. Apparently the WAF has been turned on which uses a proxy and changes the user's IP address. i'm trying to use IP address to filter "internal" traffic for Google Analytics and the only way this works is with the WAF turned off. If not using the WAF is going to cause any sort of significant risk for my website, then obviously I'll need another way to do my analytics thing. Reading about what all it provides on their website doesn't make it all that clear to me how important it is for a website like this. If anyone who "gets it" had some insight to share, I'd be most appreciative. thx!


Solution

  • You should definitely use the WAF - it will protect your website from many malicious bots and attacks.

    Wordpress sites are particularly juicy targets for attackers, for a number of reasons:

    1. The security of a default Wordpress installation is not great.

    2. Every Wordpress site shares common default features, such as the location of the admin login page, the admin username, and other exploitative resources.

    3. Wordpress is extremely popular, and currently used by an estimated third of all websites on the internet.

    4. Wordpress is used by many, many small businesses and hobbyists who do not how to secure their site properly.

    Ergo, attackers can very easily scour the web for Wordpress websites that are easily hackable. Other nefarious activities are commonly carried out with ease on most Wordpress sites, such as comment spam or Denial of Service attacks.


    What protection does the WAF offer?

    Cloudflare and most other high quality WAFs can be configured to protect your site by automatically performing actions like:

    • Blocking known bad IP addresses.
    • Blocking bad bots which are automatically making requests to your site.
    • Limiting high numbers of requests from one source in a short amount of time (usually a sign of a DoS attack or scraping).
    • Blocking requests from particular countries or locations.

    There is no reason why you wouldn't want to enable this protection if you have it available to you, and Cloudflare is the industry leader in this area.

    Additionally, I would recommend you research how to better secure your Wordpress site in ways other than just the WAF - e.g. The Ultimate WordPress Security Guide


    How to solve the IP address issue

    Cloudflare is not changing the user's (the client) IP address, but rather acting as a proxy. As you have noticed, the IP address you're seeing is not the client's own, but one of Cloudflare's. This is crucial to how Cloudflare works to protect your site, but this is a common issue when using any kind of proxy.

    To get the correct IP address when using a proxy, you need to check the X-FORWARDED-FOR header. You might see this as a string of comma-separated IP addresses, depending on how many proxies the user has gone through before reaching the site. The first one in the list is the original client IP.

    e.g. Here 203.0.113.1 is the client's original IP address:

    X-Forwarded-For: 203.0.113.1,198.51.100.101,198.51.100.102
    

    Documentation: How does Cloudflare handle HTTP Request headers?

    Anyway, it's good to use a function which can comprehensively check headers and give you the best match for the original client IP, regardless of whether the user is behind a proxy or not, so that you can guarantee it always works.

    Here's a very popular StackOverflow question about this:

    What is the most accurate way to retrieve a user's correct IP address in PHP?