Xer0x's Underground

Cloudflare is Awesome!


License

Disclaimer & Intro


This post has been made as my notes, even though I attempt to explain what I have setup/built and how, I do not owe anyone any explanation. Do NOT expect anything.


My blog is my garden.


Cloudflare as a service/company is truly awesome! I cannot stress on this enough.


Before I started using/recommending cloudflare free plan to almost every client/friend, I used to prefer cPanel based cheap-cost hosting for most of the projects/solutions/clients out there.


if you have been living under a rock for some time and have not seen/heard about cloudflare, let me put it this way:


Cloudflare is the only platform in the world that allows you to do all of these things for free:



Custom WAF Rules


Below are some rules I always deploy for any project/site/client (almost always) regardless the nature of their undertaking.


Cloudflare Page Shield


Nothing much to say here, Make sure to turn on Page Shield inside Security.

Screenshot 2025-01-19 at 12


Other Options


Basic Bot Block + AI Bot Block


Goto Security->Bots and turn on the both the options in there:


Screenshot 2025-01-19 at 12


Security Level


I like to run all my sites in "HIGH" security level but medium also works.


Screenshot 2025-01-19 at 12


Optimizations/Speed


You probably should enable these options for improving the performance of your website:


In Speed->Optimization->Content Optimization :


  1. Speed Brain
  2. Cloudflare Fonts
  3. Early Hints
  4. Smart Hints
  5. Rocket Loaderâ„¢

Screenshot 2025-01-19 at 12

Screenshot 2025-01-19 at 12


In Speed->Optimization->Protocol Optimization :


  1. HTTP/2 to Origin
  2. HTTP/3 (with QUIC)
  3. 0-RTT Connection Resumption

Screenshot 2025-01-19 at 12


In Speed->Optimization->Other :


  1. AMP Real URL

Screenshot 2025-01-19 at 12


You may also play around with other Cloudflare Rules like Compression Rules. I usually just use ZSTD with ALL INCOMING REQUESTS.


I have been hit with DDOS attacks multiple times, which CF has been able to mitigate within an hour. Below is the first DDOS this site was ever hit with:


WhatsApp Image 2025-01-08 at 09

WhatsApp Image 2025-01-08 at 09


That is it! Hope this post empowers you to point your domain to CF and test it out for yourself!


gladgers-hacker-gers-guardians-of-galaxy



Twitter LinkedIn Contact me on Signal

Contact me via email


#Web Hosting #cyber security #development #dns #https #research

← Back to blog