Skip to content

Protect from web attacks like WAF does? #2404

@ra-at-diladele-com

Description

@ra-at-diladele-com

If a client sends requests like this - can we block them?

 [22/Jan/2026:13:00:52 +0000] 195.201.233.183 "GET /root/.env HTTP/1.1" 404 134 "-" "curl/8.7.1"
 [22/Jan/2026:13:00:52 +0000] 195.201.233.183 "GET /.env.bak HTTP/1.1" 404 134 "-" "curl/8.7.1"
 [22/Jan/2026:13:00:52 +0000] 195.201.233.183 "GET /marketing/.env.staging HTTP/1.1" 404 134 "-" "curl/8.7.1"
 [22/Jan/2026:13:00:52 +0000] 195.201.233.183 "GET /.env_backup HTTP/1.1" 404 134 "-" "curl/8.7.1"
 [22/Jan/2026:13:00:52 +0000] 195.201.233.183 "GET /.git/logs/refs/heads/master HTTP/1.1" 404 134 "-" "curl/8.7.1"

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions