Skip to main content
← Changelog

Stronger Firewall Protection Across Every Site

Basker's web application firewall now covers media and theme delivery as well as public sites, and enforces a broader set of rules against exploit scanners.

Public arts websites attract a constant background of automated probing: requests for content-management login paths, configuration files, and abandoned scripts that were never part of your site. Firewall coverage now extends across public sites and the networks that deliver media and themes, with a broader rule set enforced on every request, so more of that traffic is stopped at the edge instead of reaching your pages.

Measured before it was enforced

Each new rule ran in observation mode first, recording what it would have stopped across weeks of real traffic before anything was enforced. That analysis confirmed which rules were safe to graduate, and it caught the exceptions worth keeping: ticketing callbacks and email image services that arrive without a browser signature are explicitly exempt, and search engine crawlers continue as before. Scanner probes moved to blocking only after ten thousand consecutive matches turned out to be junk with no legitimate requester among them.

What it protects against

Common exploit patterns, known bad inputs, and traffic from addresses with a poor reputation are all evaluated on every request, alongside request rates from individual sources. On public sites, attempts at file inclusion and requests for configuration and version-control files are now refused outright. The whole layer is invisible to visitors and to editors, and it makes no difference to how your site is built or published.

Improvement Security