Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 16 additions & 1 deletion src/content/docs/waf/detections/malicious-uploads/index.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ This means a request whose content was only partly scanned can produce the same
:::note[Notes]

- The AV scanner will not scan some particular types of files, namely the following:
- Password-protected archives
- Password-protected files. Refer to [Encrypted content](#encrypted-content) for supported file types.
- Archives with more than three recursion levels
- Archives with more than 300 files
- PGP-encrypted files
Expand All @@ -91,6 +91,19 @@ This means a request whose content was only partly scanned can produce the same

:::

## Encrypted content

Content scanning detects when a content object is password-protected (encrypted), for the following file types:

- ZIP archives
- RAR archives
- PDF files
- Microsoft Office files (`.docx`, `.doc`, `.xlsx`, `.xls`, `.pptx`, `.ppt`)

When content scanning detects an encrypted content object, it sets `cf.waf.content_scan.has_encrypted_obj` to `true`. The scanner cannot determine whether encrypted content is malicious, so the content object's result in `cf.waf.content_scan.obj_results` is reported as `not scanned`, and `cf.waf.content_scan.has_failed` is not set for encrypted content.

To block or challenge encrypted uploads, use `cf.waf.content_scan.has_encrypted_obj` in a custom rule.

## Custom scan expressions

Sometimes, you may want to specify where to find the content objects, such as when the content is a Base64-encoded string within a JSON payload. For example:
Expand Down Expand Up @@ -118,6 +131,7 @@ When content scanning is enabled, you can use the following fields in WAF rules:
| Number of malicious content objects <br/> [`cf.waf.content_scan.num_malicious_obj`][3] <br/> <Type text="Integer" /> | The number of malicious content objects detected in the request (zero or greater). |
| Content scan has failed <br/> [`cf.waf.content_scan.has_failed`][4] <br/> <Type text="Boolean" /> | Indicates whether the file scanner was unable to scan any of the content objects detected in the request. |
| Content scan truncated <br/> [`cf.waf.content_scan.truncated`][9] <br/> <Type text="Boolean" /> | Indicates whether the request body exceeded the size limit for content scanning and was truncated before scanning, meaning the scan results may be incomplete. Refer to [Size limit](#size-limit). |
| Has encrypted content object <br/> [`cf.waf.content_scan.has_encrypted_obj`][10] <br/> <Type text="Boolean" /> | Indicates whether the request contains at least one password-protected (encrypted) content object. Refer to [Encrypted content](#encrypted-content). |
| Number of content objects <br/> [`cf.waf.content_scan.num_obj`][5] <br/> <Type text="Integer" /> | The number of content objects detected in the request (zero or greater). |
| Content object size <br/> [`cf.waf.content_scan.obj_sizes`][6] <br/> <Type text="Array<Integer>" /> | An array of file sizes in bytes, in the order the content objects were detected in the request. |
| Content object type <br/> [`cf.waf.content_scan.obj_types`][7] <br/> <Type text="Array<String>" /> | An array of file types in the order the content objects were detected in the request. |
Expand All @@ -132,5 +146,6 @@ When content scanning is enabled, you can use the following fields in WAF rules:
[7]: /ruleset-engine/rules-language/fields/reference/cf.waf.content_scan.obj_types/
[8]: /ruleset-engine/rules-language/fields/reference/cf.waf.content_scan.obj_results/
[9]: /ruleset-engine/rules-language/fields/reference/cf.waf.content_scan.truncated/
[10]: /ruleset-engine/rules-language/fields/reference/cf.waf.content_scan.has_encrypted_obj/

For examples of rule expressions using these fields, refer to [Example rules](/waf/detections/malicious-uploads/example-rules/).
22 changes: 22 additions & 0 deletions src/content/fields/index.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -1220,6 +1220,28 @@ entries:
# Block requests to a specific endpoint whose content was not fully scanned
cf.waf.content_scan.truncated and http.request.uri.path eq "/upload"

- name: cf.waf.content_scan.has_encrypted_obj
data_type: Boolean
categories: [Request]
keywords:
[
request,
cloudflare,
content scanning,
malicious uploads,
client,
visitor,
]
plan_info_label: Enterprise add-on
summary: Indicates whether the request contains at least one password-protected (encrypted) content object.
description: |-
Requires a Cloudflare Enterprise plan with [malicious uploads detection](/waf/detections/malicious-uploads/).

Refer to [Encrypted content](/waf/detections/malicious-uploads/#encrypted-content) for the file types this field covers.
example_block: |-
# Block requests containing password-protected uploads
cf.waf.content_scan.has_encrypted_obj and http.request.uri.path eq "/upload"

- name: cf.waf.content_scan.num_obj
data_type: Integer
categories: [Request]
Expand Down