Hướng dẫn giải pháp Solution guide មគ្គុទ្ទេសករណ៍ដំណោះស្រាយ Application Services Application Services Application Services ~10 phút ~10 min ~10 នាទី Đồng bộ 2026-06-10 Synced 2026-06-10 ធ្វើសមកាល 2026-06-10

Ngăn chặn các cuộc tấn công mua lại tài khoản (Miễn phí, Pro và Doanh nghiệp) Stop account takeover attacks (Free, Pro, and Business) កាត់បន្ថយការជួញដូរគណនី (ដោយឥតគិតថ្លៃ, Pro និង Business)

Hướng dẫn chi tiết đồng bộ từ docs Cloudflare — mỗi section có backlink tới đúng vị trí trên trang gốc. Detailed guide synced from Cloudflare docs — each section links to the matching anchor on the official page. មគ្គុទ្ទេសក៍លម្អិតធ្វើសមកាលពី docs Cloudflare — ផ្នែកនីមួយៗមានតំណទៅទីតាំងត្រូវគ្នានៅទំព័រផ្លូវការ។

← Danh mục ← Catalog ← បញ្ជី

Giải thích nhanh Quick context បរិបទរហ័ស

Thuộc nhóm Application Services — tập trung bảo vệ, tăng tốc và vận hành ứng dụng/web phía trước origin. Tutorial «Stop account takeover attacks (Free, Pro, và Business)» giúp bạn làm quen luồng triển khai thật — phù hợp đọc trước khi mở tài liệu gốc tiếng Anh. Đọc phần tóm tắt và lưu ý trước — sau đó mở docs gốc để copy lệnh và cấu hình chi tiết.

Block credential stuffing and brute force attacks on login endpoints using a layered defense.

Block credential stuffing and brute force attacks on login endpoints using a layered defense ។

Lưu ý Note ចំណាំ

Lưu ý trước khi làm Notes before you start ចំណាំមុនពេលចាប់ផ្តើម

  • Đây là bản tóm tắt trên Orange Cloud Learning Hub — không thay thế tài liệu chính thức.
  • Luôn mở liên kết «Tài liệu gốc» bên dưới khi cần lệnh CLI, snippet code và ảnh minh họa đầy đủ.
  • Docs Cloudflare cập nhật thường xuyên — đối chiếu ngày «Rà soát lần cuối» trên trang gốc khi triển khai production.
  • This is a summary on Orange Cloud Learning Hub — it does not replace the official documentation.
  • Open the Official docs link below for CLI commands, code snippets, and full screenshots.
  • Cloudflare docs change frequently — verify the Last reviewed date on the official page before production use.
  • នេះគឺជាការបញ្ជាក់អំពី Orange Cloud Learning Hub — វាគឺជាការផ្លាស់ប្តូរនៃឯកសារផ្លូវការ។
  • ចុចតំណភ្ជាប់ Docs Official នៅខាងក្រោមសម្រាប់ការបញ្ជា CLI, សៀវភៅកូដនិងរូបថតពេញលេញ។
  • Cloudflare បានផ្លាស់ប្តូរជាធម្មតានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅ។

Overview Overview Overview

Phần «Tổng quan» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Overview" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «Overview» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Khi trang web của bạn có đăng nhập pages, bạn cần quyết định làm thế nào để xác minh rằng khách truy cập là con người, làm thế nào tích cực để hạn chế các nỗ lực thất bại, và yêu cầu mẫu nào để chặn. Hướng dẫn này bao gồm năm giai đoạn: thực thi HTTPS, bật bảo vệ bot, thêm Turnstile vào đăng nhập của bạn form, tạo Application Security rate limiting rules và custom rules cho các mô hình đáng ngờ, và giám sát các cuộc tấn công đang diễn ra bằng cách sử dụng SSL/TLS bảo mật giao thông và Cloudflare bot solutions. Quá trình làm việc cốt lõi bao gồm các tính năng có sẵn trên các gói miễn phí, Pro và Business. Các tính năng doanh nghiệp như vị trí phát hiện tùy chỉnh thông tin bị rò rỉ và quy tắc tùy chỉnh Bot Management được bao gồm dưới dạng cuộc gọi.
When your site has login pages, you need to decide how to verify that visitors are human, how aggressively to limit failed attempts, and which request patterns to block. This guide covers five stages: enforce HTTPS, turn on bot protection, add Turnstile to your login form, create Application Security rate limiting rules and custom rules for suspicious patterns, and monitor for ongoing attacks using SSL/TLS transport security and Cloudflare bot solutions. The core workflow covers features available on Free, Pro, and Business plans. Enterprise features such as leaked credentials custom detection locations and Bot Management custom rules are included as callouts.
នៅពេលដែលគេហទំព័ររបស់អ្នកមានការចូលរួម pages, អ្នកត្រូវដោះស្រាយអំពីរបៀបដើម្បីត្រួតពិនិត្យថាមានអ្នកចូលរួមជាមនុស្ស, តើធ្វើដូចម្តេចដើម្បីកាត់បន្ថយការធ្វើតេស្តដែលមិនបានជោគជ័យនិងរបៀបទម្រង់ដើម្បីកាត់បន្ថយ។ វគ្គបណ្តុះបណ្តាលនេះរួមបញ្ចូលទាំង 5 ដំណាក់កាល: ការអនុវត្ត HTTPS, ការផ្លាស់ប្តូរការពារ bot, ការផ្លាស់ប្តូរ Turnstile ទៅ form របស់អ្នក, ការបង្កើតកម្មវិធីសុវត្ថិភាព rate limiting rules និង custom rules សម្រាប់គំរូគួរឱ្យចាប់អារម្មណ៍, និងការត្រួតពិនិត្យសម្រាប់ការប៉ះពាល់បច្ចុប្បន្នដោយប្រើ SSL/TLS ការពារដឹកជញ្ជូននិង Cloudflare bot solutions ។ ប្រព័ន្ធប្រតិបត្តិការទូទាត់នេះអាចប្រើបាននៅលើទូទាត់ Free, Pro និង Business ។ លក្ខណៈពិសេសឧស្សាហកម្មដូចជាកន្លែងការរកឃើញផ្ទាល់ខ្លួនដែលបានបំពាក់និង Bot Management គោលដៅផ្ទាល់ខ្លួនត្រូវបានរួមបញ្ចូលជា Callouts ។
Hầu hết các thủ tục trong hướng dẫn này được cấu hình theo tên miền hoặc zone. Chọn tên miền của bạn trong bảng điều khiển Cloudflare trước khi bắt đầu. Turnstile là ngoại lệ: widget được cấu hình ở cấp độ tài khoản.
Most procedures in this guide are configured per domain or zone. Select your domain in the Cloudflare dashboard before starting. Turnstile is the exception: widgets are configured at the account level.
ភាគច្រើននៃដំណើរការនៅក្នុងឧបករណ៍នេះត្រូវបានកំណត់តាមតំបន់ឬ zone ។ សូមជ្រើសរើសឧបករណ៍របស់អ្នកនៅក្នុងឧបករណ៍ Cloudflare មុនពេលចាប់ផ្តើម។ Turnstile គឺជាការប៉ះពាល់: widgets ត្រូវបានកំណត់នៅលើកម្រិតគណនី។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Áp dụng HTTPS để bảo vệ thông tin trong quá cảnh Enforce HTTPS to protect credentials in transit ការអនុវត្ត HTTPS ដើម្បីការពារវិញ្ញាបនប័ត្រក្នុងដំណើរការ

Phần «Enforce HTTPS to protect credentials in transit» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Enforce HTTPS to protect credentials in transit" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការអនុវត្ត HTTPS ដើម្បីការពារវិញ្ញាបនប័ត្រក្នុងដំណើរការ» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Thông tin xác thực được gửi qua HTTP hiển thị cho bất cứ ai trên đường dẫn mạng giữa khách truy cập và máy chủ nguồn của bạn. Cloudflare SSL/TLS cung cấp hai thiết đặt thực thi kết nối HTTPS: Always Use HTTPS và HTTP Strict Transport Security (HSTS). Để kiểm soát thêm các tiêu chuẩn mã hóa mà tên miền của bạn chấp nhận, hãy tham khảo Cipher suites.
Credentials sent over plain HTTP are visible to anyone on the network path between the visitor and your origin server. Cloudflare SSL/TLS provides two settings that enforce HTTPS connections: Always Use HTTPS and HTTP Strict Transport Security (HSTS). For additional control over which encryption standards your domain accepts, refer to Cipher suites.
វិញ្ញាបនប័ត្រដែលបានផ្ញើនៅលើ HTTP គឺអាចមើលឃើញដល់អ្នកណាមួយនៅលើផ្លូវបណ្តាញរវាងអ្នកទស្សនានិងសេវាកម្មដើមរបស់អ្នក។ Cloudflare SSL/TLS ផ្តល់នូវកំណត់ពីរដែលអនុវត្តការតភ្ជាប់ HTTPS: Always Use HTTPS និង HTTP Strict Transport Security (HSTS) ។ សម្រាប់ការត្រួតពិនិត្យបន្ថែមទៀតអំពីការត្រួតពិនិត្យស្ដង់ដារអាសយដ្ឋានរបស់អ្នកដែលទទួលបានអាសយដ្ឋានរបស់អ្នក, សូមមើល Cipher suites ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Chuyển sang Always Use HTTPS Turn on Always Use HTTPS ទាញយក Always Use HTTPS

Phần «Turn on Always Use HTTPS» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Turn on Always Use HTTPS" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ទាញយក Always Use HTTPS» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Always Use HTTPS chuyển hướng tất cả các yêu cầu của khách truy cập từ http sang https cho tất cả các tên miền con và máy chủ.
Always Use HTTPS redirects all visitor requests from http to https for all subdomains and hosts.
Always Use HTTPS អនុញ្ញាតឱ្យអ្នកស្វែងរកទាំងអស់ពី http ទៅ https សម្រាប់ឧបករណ៍អតិថិជនទាំងអស់។
Để kích hoạt Always Use HTTPS trong bảng điều khiển:
To enable Always Use HTTPS in the dashboard:
ដើម្បីអនុញ្ញាតឱ្យ Always Use HTTPS ក្នុង dashboard នេះ:
  1. Trong bảng điều khiển Cloudflare, đi đến trang SSL/TLS Overview.
  1. In the Cloudflare dashboard, go to the SSL/TLS Overview page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ SSL/TLS Overview ។
  1. Đảm bảo rằng SSL/TLS encryption mode của bạn không được đặt thành Off. Khi bạn đặt chế độ mã hóa thành Off, tùy chọn Always Use HTTPS sẽ không hiển thị trong bảng điều khiển Cloudflare của bạn.
  2. Đi đến trang Edge Certificates ↗.
  3. Nhấp vào Always Use HTTPS
  1. Make sure that your SSL/TLS encryption mode is not set to Off. When you set your encryption mode to Off, the Always Use HTTPS option will not be visible in your Cloudflare dashboard.
  2. Go to the Edge Certificates ↗ page.
  3. Turn on Always Use HTTPS.
  1. សូមបញ្ជាក់ថា SSL/TLS encryption mode របស់អ្នកមិនត្រូវបានកំណត់ទៅ Off ។ ប្រសិនបើអ្នកបានកំណត់ម៉ូដអាសយដ្ឋានអាសយដ្ឋានអាសយដ្ឋានរបស់អ្នកទៅ Off អ្នកនឹងមិនមើលឃើញតម្រូវការ Always Use HTTPS នៅលើប្រព័ន្ធប្រតិបត្តិការរបស់អ្នក Cloudflare ។
  2. សូមចូលទៅក្នុងទំព័រ Edge Certificates ↗ ។
  3. សូមចុច Always Use HTTPS ។
Để bật hoặc vô hiệu hóa Always Use HTTPS với API:
To enable or disable Always Use HTTPS with the API:
ដើម្បីអនុញ្ញាតឱ្យប្រសើរឡើងឬប្រសើរឡើង Always Use HTTPS ជាមួយ API:
  1. Đảm bảo rằng SSL/TLS encryption mode is not của bạn được đặt thành Off.
  2. Gửi yêu cầu PATCH với always<em>use</em>https làm tên cài đặt trong đường dẫn URI, và tham số value được đặt vào cài đặt mong muốn của bạn ("on" hoặc "off").
  1. Make sure that your SSL/TLS encryption mode is not set to Off.
  2. Send a PATCH request with always<em>use</em>https as the setting name in the URI path, and the value parameter set to your desired setting ("on" or "off").
  1. សូមបញ្ជាក់ថា SSL/TLS encryption mode is not គឺជា Off ។
  2. សូមផ្ញើទម្រង់ PATCH ជាមួយ always<em>use</em>https ជាឈ្មោះកំណត់នៅក្នុងផ្លូវ URI និងទំហំ value បានកំណត់ទៅនឹងកំណត់ដែលអ្នកចង់ ("on" ឬ "off") ។
Cloudflare khuyên bạn không nên thực hiện chuyển hướng tại máy chủ web gốc của bạn, vì điều này có thể gây ra redirect loop errors.
Cloudflare recommends not performing redirects at your origin web server, as this can cause redirect loop errors.
Cloudflare អនុញ្ញាតឱ្យអ្នកមិនធ្វើដំណើរការ redirect នៅលើបណ្តាញដើមរបស់អ្នក, ដូច្នេះវាអាចធ្វើឱ្យ redirect loop errors ។
Tùy chọn: HTTP An toàn giao thông nghiêm ngặt (HSTS)
Optional: HTTP Strict Transport Security (HSTS)
គោលបំណង: HTTP គោលបំណងសុវត្ថិភាពការដឹកជញ្ជូន (HSTS)
Để tăng cường vận chuyển thêm, hãy xem xét kích hoạt HTTP Strict Transport Security (HSTS). HSTS bảo các trình duyệt chỉ kết nối qua HTTPS, ngăn chặn các cuộc tấn công hạ cấp trên yêu cầu ban đầu. HSTS là không thể đảo ngược cho thời gian Max Age được cấu hình. Nếu sau đó bạn vô hiệu hóa HTTPS, trang web của bạn sẽ không thể truy cập được cho đến khi Max Age hết hạn. Xem lại HSTS requirements trước khi bật nó.
For additional transport hardening, consider enabling HTTP Strict Transport Security (HSTS). HSTS tells browsers to only connect over HTTPS, preventing downgrade attacks on the initial request. HSTS is irreversible for the configured Max Age duration. If you later disable HTTPS, your site becomes inaccessible until the Max Age expires. Review the HSTS requirements before turning it on.
សម្រាប់ការកាត់បន្ថយការដឹកជញ្ជូនបន្ថែម, សូមពិនិត្យមើលការអនុញ្ញាត HTTP Strict Transport Security (HSTS) ។ HSTS អនុញ្ញាតឱ្យអ្នកបង្វិលដើម្បីតភ្ជាប់តាមរយៈ HTTPS ដោយគ្មានការជួបប្រទះទំហំទូលាយនៅលើសំណួរដំបូង។ HSTS គឺជាការប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែ ប្រសិនបើអ្នកជួសជុល HTTPS បន្ទាប់មកអ្នកនឹងក្លាយជាគេហទំព័ររបស់អ្នកមិនអាចរកបានទៅដល់ពេលដែលអាយុអតិបរមាបានបញ្ចប់។ សូមពិនិត្យមើល HSTS requirements មុនពេលផ្លាស់ប្តូរវា។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Chuyển sang Bot Protection Turn on bot protection ចុចលើការពារ bot

Phần «Turn on bot protection» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Turn on bot protection" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ចុចលើការពារ bot» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Cloudflare cung cấp bảo vệ bot trên tất cả các kế hoạch, với các tính năng khác nhau theo cấp kế hoạch. Bật bảo vệ bot trước khi cấu hình các quy tắc cụ thể cho đăng nhập cho bạn một bộ lọc cơ bản chống lại lưu lượng truy cập tự động trên toàn bộ tên miền của bạn.
Cloudflare provides bot protection on all plans, with features that vary by plan tier. Turning on bot protection before configuring login-specific rules gives you a baseline filter against automated traffic across your entire domain.
Cloudflare ផ្តល់នូវការពារ bot នៅលើទម្រង់ទាំងអស់, ជាមួយនឹងលក្ខណៈពិសេសដែលផ្សេងគ្នានៃទម្រង់។ ការផ្លាស់ប្តូរការពារ bot មុនពេលកំណត់ធម្មតានតម្រូវការដែលមានលក្ខណៈពិសេសសម្រាប់ការចូលរួមផ្តល់ឱ្យអ្នកនូវការត្រួតពិនិត្យមូលដ្ឋានប្រឆាំងនឹងការដឹកជញ្ជូនដោយស្វ័យប្រវត្តិនៅទូទាំងអាសយដ្ឋានរបស់អ្នក។

Bot Fight Mode (Miễn phí) Bot Fight Mode (Free) Bot Fight Mode (ដោយឥតគិតថ្លៃ)

Phần «Bot Fight Mode (Free)» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Bot Fight Mode (Free)" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «Bot Fight Mode (ដោយឥតគិតថ្លៃ)» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Bot Fight Mode thách thức các yêu cầu phù hợp với các mô hình bot đã biết. Nó áp dụng cho tất cả lưu lượng truy cập trên tên miền của bạn và không thể được tùy chỉnh với các ngoại lệ hoặc quy tắc cụ thể.
Bot Fight Mode challenges requests that match known bot patterns. It applies to all traffic on your domain and cannot be customized with exceptions or path-specific rules.
ការធ្វើតេស្ត Bot Fight Mode មានតម្រូវការដែលសមរម្យជាមួយគំរូ bot ដែលបានដឹង។ វាត្រូវបានអនុវត្តសម្រាប់ការដឹកជញ្ជូនទាំងអស់នៅលើតំបន់របស់អ្នកហើយមិនអាចត្រូវបានកំណត់ដោយគ្មានលក្ខខណ្ឌលក្ខខណ្ឌឬច្បាប់ពិសេស។
  1. Trong bảng điều khiển Cloudflare, đi đến trang Security Settings.
  1. In the Cloudflare dashboard, go to the Security Settings page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Security Settings ។
  1. Lọc theo Bot traffic
  2. Đi đến Bot fight mode
  3. Nhấn Bot fight mode vào.
  1. Filter by Bot traffic.
  2. Go to Bot fight mode.
  3. Turn Bot fight mode on.
  1. កញ្ចប់ដោយ Bot traffic
  2. សូមចូលទៅ Bot fight mode ។
  3. ចុច Bot fight mode នៅលើ។
  1. Đăng nhập vào Cloudflare dashboard ↗ và chọn tài khoản và tên miền của bạn.
  2. Đi đến Security \> Bots.
  3. Đối với Bot Fight Mode, hãy chọn On.
  1. Log in to the Cloudflare dashboard ↗, and select your account and domain.
  2. Go to Security \> Bots.
  3. For Bot Fight Mode, select On.
  1. ចុច Cloudflare dashboard ↗ ហើយជ្រើសគណនីរបស់អ្នកនិងតំបន់បណ្ដាញរបស់អ្នក។
  2. ចុចទៅ Security \> Bots ។
  3. សម្រាប់ Bot Fight Mode ចុច On ។
Bot Fight Mode không thể bỏ qua các quy tắc tùy chỉnh vì nó không chạy bên trong Ruleset Engine. Nếu bạn cần loại trừ lưu lượng truy cập cụ thể (các công cụ giám sát, API đối tác), hãy nâng cấp lên chế độ Super Bot Fight trên gói Pro.
Bot Fight Mode cannot be skipped by custom rules because it does not run inside the Ruleset Engine. If you need to exempt specific traffic (monitoring tools, partner APIs), upgrade to Super Bot Fight Mode on the Pro plan.
Bot Fight Mode មិនអាចត្រូវបានបាត់បង់ដោយច្បាប់ផ្ទាល់ខ្លួនដោយសារតែវាមិនដំណើរការនៅខាងក្នុងនៃម៉ាស៊ីន Ruleset ។ ប្រសិនបើអ្នកត្រូវការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុញ្ញាតការអនុវត្ត។

Chế độ Super Bot Fight Mode (Pro, Business và Enterprise) Super Bot Fight Mode (Pro, Business, and Enterprise) Super Bot Fight Mode (អាជីវកម្មនិងអាជីវកម្ម)

Phần «Super Bot Fight Mode (Pro, Business, và Enterprise)» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Super Bot Fight Mode (Pro, Business, and Enterprise)" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «Super Bot Fight Mode (អាជីវកម្មនិងអាជីវកម្ម)» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Chế độ Super Bot Fight xác định các mô hình giao thông phù hợp với các bot đã biết, có thể thách thức hoặc chặn các bot, và cung cấp bảo vệ cho các tài nguyên tĩnh. Bạn cấu hình một action riêng biệt cho mỗi nhóm bot: Definitely automated, Likely automated và Verified bots. Bạn cũng có thể configure exceptions bằng cách sử dụng Application Security custom rules với Skip action.
Super Bot Fight Mode identifies traffic matching patterns of known bots, can challenge or block bots, and offers protection for static resources. You configure a separate action for each bot grouping: Definitely automated, Likely automated, and Verified bots. You can also configure exceptions using Application Security custom rules with the Skip action.
Super Bot Fight Mode អនុញ្ញាតឱ្យអ្នករកឃើញទំហំដំណើរការដែលសម្តែងជាមួយនឹងប្លាស្ទិចរបស់ប្លាស្ទិចដែលដឹងថាអ្នកអាចជម្រើសឬកាត់បន្ថយប្លាស្ទិចនិងផ្តល់ការពារសម្រាប់សមាសធាតុធម្មតា។ អ្នកនឹងកំណត់ action មួយសម្រាប់ការកំណត់បណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តាល: Definitely automated, Likely automated និង Verified bots ។ អ្នកក៏អាចប្រើ configure exceptions ដោយប្រើកម្មវិធីសុវត្ថិភាព custom rules ជាមួយនឹង Skip action ។
Nếu bạn đang nâng cấp từ Chế độ Chiến đấu Bot lên Chế độ Chiến đấu Super Bot, bạn phải vô hiệu hóa Chế độ Chiến đấu Bot trong cài đặt Bot của bạn.
If you are upgrading from Bot Fight Mode to Super Bot Fight Mode, you must disable Bot Fight Mode in your Bot settings.
ប្រសិនបើអ្នកកំពុងធ្វើការអភិវឌ្ឍន៍ពី Bot Fight Mode ទៅ Super Bot Fight Mode, អ្នកត្រូវការកាត់បន្ថយ Bot Fight Mode នៅក្នុងកំណត់ Bot របស់អ្នក។
  • Bảng điều khiển cũ: Security \> Bots, và chọn Configure Bot Fight Mode.
  • Bảng điều khiển mới: Security \> Settings. Chọn Bot traffic và tắt Bot fight mode.
  • Old dashboard: Security \> Bots, and select Configure Bot Fight Mode.
  • New dashboard: Security \> Settings. Filter by Bot traffic and turn Bot fight mode off.
  • ប្រព័ន្ធប្រតិបត្តិការទូទៅ: Security & > Bots, និងចុច Configure Bot Fight Mode ។
  • ស្លាកថ្មី: Security \> Settings ។ ចុច Bot traffic ហើយចុច Bot fight mode ។
  1. Trong bảng điều khiển Cloudflare, đi đến trang Security Settings.
  1. In the Cloudflare dashboard, go to the Security Settings page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Security Settings ។
  1. Lọc theo Bot traffic
  2. Đi đến Super Bot fight mode
  3. Nhấn Super Bot fight mode vào.
  4. Chọn cách miền của bạn nên đáp ứng với các loại lưu lượng truy cập khác nhau bằng cách chọn biểu tượng chỉnh sửa liên quan:
  1. Filter by Bot traffic.
  2. Go to Super Bot fight mode.
  3. Turn Super Bot fight mode on.
  4. Choose how your domain should respond to various types of traffic by selecting the associated edit icon:
  1. កញ្ចប់ដោយ Bot traffic
  2. សូមចូលទៅ Super Bot fight mode ។
  3. ចុច Super Bot fight mode នៅលើ។
  4. ជ្រើសរើសរបៀបដែលអាសយដ្ឋានរបស់អ្នកគួរឱ្យឆ្លើយតបទៅនឹងប្រភេទផ្សេងគ្នានៃការដឹកជញ្ជូនដោយជ្រើសរើសអេឡិចត្រូនិ edit ដែលរួមបញ្ចូលគ្នា:
Để biết thêm chi tiết về các bot đã được xác minh, hãy tham khảo Verified Bots. Để biết thêm chi tiết về các loại tệp được hỗ trợ, hãy tham khảo Static resource protection. Để biết thêm chi tiết về tiêm mã vô hình, hãy xem JavaScript detections. Để biết thêm chi tiết về tối ưu hóa WordPress, hãy tham khảo Super Bot Fight Mode for WordPress.
For more details on verified bots, refer to Verified Bots. For more details on supported file types, refer to Static resource protection. For more details on invisible code injection, refer to JavaScript detections. For more details on WordPress optimization, refer to Super Bot Fight Mode for WordPress.
សម្រាប់ព័ត៌មានបន្ថែមអំពី bots ដែលបានត្រួតពិនិត្យមើល Verified Bots ។ សម្រាប់ព័ត៌មានបន្ថែមអំពីប្រភេទឯកសារដែលគាំទ្រមើល Static resource protection ។ សម្រាប់ព័ត៌មានបន្ថែមអំពីការដំឡើងលេខកូដគិតថ្លៃសូមមើល JavaScript detections ។ សម្រាប់ព័ត៌មានបន្ថែមអំពីការធ្វើឱ្យប្រសើរឡើង WordPress សូមមើល Super Bot Fight Mode for WordPress ។
  1. Đăng nhập vào Cloudflare dashboard ↗ và chọn tài khoản và tên miền của bạn.
  2. Đi đến Security \> Bots.
  3. Chọn Configure Super Bot Fight Mode
  4. Chọn cách miền của bạn nên đáp ứng với các loại lưu lượng truy cập khác nhau:
  1. Log in to the Cloudflare dashboard ↗, and select your account and domain.
  2. Go to Security \> Bots.
  3. Select Configure Super Bot Fight Mode.
  4. Choose how your domain should respond to various types of traffic:
  1. ចុច Cloudflare dashboard ↗ ហើយជ្រើសគណនីរបស់អ្នកនិងតំបន់បណ្ដាញរបស់អ្នក។
  2. ចុចទៅ Security \> Bots ។
  3. សូមជ្រើស Configure Super Bot Fight Mode ។
  4. ជ្រើសរើសរបៀបដែលអាសយដ្ឋានរបស់អ្នកគួរឱ្យឆ្លើយតបទៅនឹងប្រភេទផ្សេងគ្នានៃការដឹកជញ្ជូន:
Để biết thêm chi tiết về các bot đã được xác minh, hãy tham khảo Verified Bots. Để biết thêm chi tiết về các loại tệp được hỗ trợ, hãy tham khảo Static resource protection. Để biết thêm chi tiết về tiêm mã vô hình, hãy xem JavaScript detections. Để biết thêm chi tiết về tối ưu hóa WordPress, hãy tham khảo Super Bot Fight Mode for WordPress.
For more details on verified bots, refer to Verified Bots. For more details on supported file types, refer to Static resource protection. For more details on invisible code injection, refer to JavaScript detections. For more details on WordPress optimization, refer to Super Bot Fight Mode for WordPress.
សម្រាប់ព័ត៌មានបន្ថែមអំពី bots ដែលបានត្រួតពិនិត្យមើល Verified Bots ។ សម្រាប់ព័ត៌មានបន្ថែមអំពីប្រភេទឯកសារដែលគាំទ្រមើល Static resource protection ។ សម្រាប់ព័ត៌មានបន្ថែមអំពីការដំឡើងលេខកូដគិតថ្លៃសូមមើល JavaScript detections ។ សម្រាប់ព័ត៌មានបន្ថែមអំពីការធ្វើឱ្យប្រសើរឡើង WordPress សូមមើល Super Bot Fight Mode for WordPress ។
Để bảo vệ đăng nhập, các giá trị bắt đầu sau đây được khuyến nghị. Điều chỉnh dựa trên mô hình giao thông của bạn.
For login protection, the following are recommended starting values. Adjust based on your traffic patterns.
សម្រាប់ការការពារការចូលរួមគ្នានេះមានគុណភាពចាប់ផ្តើមដូចខាងក្រោម។ ការផ្លាស់ប្តូរដោយផ្អែកលើគំរូការដឹកជញ្ជូនរបស់អ្នក
  • Definitely automated: Thách thức quản lý. Sau khi xem lại Sự kiện bảo mật để xác nhận thiết đặt không ảnh hưởng đến lưu lượng truy cập hợp pháp, hãy chuyển sang Block.
  • Likely automated: Thách thức quản lý.
  • Verified bots: Cho phép
  • Definitely automated: Managed Challenge. After reviewing Security Events to confirm the setting does not affect legitimate traffic, switch to Block.
  • Likely automated: Managed Challenge.
  • Verified bots: Allow.
  • Definitely automated: កម្រិតគ្រប់គ្រង បន្ទាប់ពីពិនិត្យមើលកម្មវិធី Security Events ដើម្បីបញ្ជាក់ថាតើការកំណត់នេះមិនមានប្រសិទ្ធិភាពលើការដឹកជញ្ជូនត្រឹមត្រូវ, សូមផ្លាស់ប្តូរទៅ Block ។
  • Likely automated: កម្រិតគ្រប់គ្រង
  • Verified bots: អនុញ្ញាត ។
Warning
Warning
Warning
Nếu tổ chức của bạn cũng sử dụng Cloudflare Tunnel, hãy giữ Definitely Automated đặt thành Allow. Nếu không, đường hầm có thể thất bại với lỗi websocket: bad handshake.
If your organization also uses Cloudflare Tunnel, keep Definitely Automated set to Allow. Otherwise, tunnels might fail with a websocket: bad handshake error.
ប្រសិនបើប្រព័ន្ធប្រតិបត្តិការរបស់អ្នកក៏ប្រើ Cloudflare Tunnel ដូច្នេះវានឹងរក្សាទុក Definitely Automated ទៅ Allow ។ ប្រសិនបើមិនបានធ្វើដូច្នេះអ្នកអាចជឿទុកចិត្តថាមាន websocket: bad handshake Error ។
Custom rules được thực hiện trước chế độ Super Bot Fight Mode. Để tạo ngoại lệ cho các tuyến đường hoặc lưu lượng truy cập cụ thể, hãy tạo quy tắc tùy chỉnh với Skip action. Skip action cho phép yêu cầu bỏ qua giai đoạn Super Bot Fight Mode mà không cần chấm dứt yêu cầu, cho phép nó tiếp tục thông qua phần còn lại của stack bảo mật.
Custom rules are executed before Super Bot Fight Mode. To create exceptions for specific paths or traffic, create a custom rule with the Skip action. The Skip action allows the request to bypass the Super Bot Fight Mode phase without terminating the request, enabling it to continue through the rest of the security stack.
Custom rules ត្រូវបានដំណើរការមុនពេល Super Bot Fight Mode ។ ប្រសិនបើអ្នកចង់បង្កើតការប៉ះពាល់សម្រាប់ដំណើរការឬដំណើរការពិសេសអ្នកអាចបង្កើតច្បាប់ផ្ទាល់ខ្លួនជាមួយ Skip action ។ កម្មវិធី Skip action អនុញ្ញាតឱ្យការទូទាត់អនុញ្ញាតឱ្យការទូទាត់អនុញ្ញាតឱ្យការទូទាត់អនុញ្ញាតឱ្យការទូទាត់អនុញ្ញាតឱ្យការទូទាត់អនុញ្ញាតឱ្យការទូទាត់អនុញ្ញាតឱ្យការទូទាត់អនុញ្ញាតឱ្យការទូទាត់អនុញ្ញាតឱ្យការទូទាត់អនុញ្ញាតឱ្យការទូទាត់អនុញ្ញាតឱ្យការទូទាត់អនុញ្ញាតឱ្យការទូទាត់អនុញ្ញាតឱ្យការទូទាត់អនុញ្ញាតឱ្យការទូទាត់អនុញ្ញាតឱ្យការទូទាត់។

Bảo vệ đăng nhập của bạn form với Turnstile và rate limiting Protect your login form with Turnstile and rate limiting ការពារការចូលរួមរបស់អ្នក form ជាមួយ Turnstile និង rate limiting

Phần «Bảo vệ your login form với Turnstile và rate limiting» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Protect your login form with Turnstile and rate limiting" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការពារការចូលរួមរបស់អ្នក form ជាមួយ Turnstile និង rate limiting» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Hai công cụ bảo vệ các điểm cuối đăng nhập khỏi lạm dụng tự động, và chúng bao gồm các vector tấn công khác nhau:
Two tools protect login endpoints from automated abuse, and they cover different attack vectors:
ឧបករណ៍ពីរដែលការពារបញ្ចប់ការចូលរួមពីការទូទាត់ដោយស្វ័យប្រវត្តិហើយពួកគេគ្របដណ្តប់បណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តាលផ្សេងគ្នា។
  • Turnstile verifies that visitors are human without showing a CAPTCHA. It can be embedded into any website without sending traffic through Cloudflare. Use Turnstile to challenge automated form submissions.
  • Application Security rate limiting rules define rate limits for requests matching an expression and the action to perform when those limits are reached. Use rate limiting to protect login endpoints from abuse, such as brute-force attacks.
  • Turnstile verifies that visitors are human without showing a CAPTCHA. It can be embedded into any website without sending traffic through Cloudflare. Use Turnstile to challenge automated form submissions.
  • Application Security rate limiting rules define rate limits for requests matching an expression and the action to perform when those limits are reached. Use rate limiting to protect login endpoints from abuse, such as brute-force attacks.
  • Turnstile verifies that visitors are human without showing a CAPTCHA. It can be embedded into any website without sending traffic through Cloudflare. Use Turnstile to challenge automated form submissions.
  • Application Security rate limiting rules define rate limits for requests matching an expression and the action to perform when those limits are reached. Use rate limiting to protect login endpoints from abuse, such as brute-force attacks.
Cả hai cùng nhau cung cấp bảo hiểm mạnh nhất. Turnstile thách thức gửi tự động ở mức form. Rate limiting bắt các cuộc tấn công khối lượng cao mà bỏ qua hoặc không gặp phải form, chẳng hạn như yêu cầu POST trực tiếp đến điểm cuối.
Both together provide the strongest coverage. Turnstile challenges automated submissions at the form level. Rate limiting catches high-volume attacks that bypass or do not encounter the form, such as direct POST requests to the endpoint.
Both together provide the strongest coverage. Turnstile challenges automated submissions at the form level. Rate limiting catches high-volume attacks that bypass or do not encounter the form, such as direct POST requests to the endpoint.

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Thêm Turnstile vào login của bạn form Add Turnstile to your login form Add Turnstile to your login form

Phần «Thêm Turnstile vào login form» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Add Turnstile to your login form" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «Add Turnstile to your login form» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Thực hiện Turnstile liên quan đến ba bước: tạo một widget, thêm đoạn trích phía khách hàng vào đăng nhập của bạn form, và xác nhận mã thông báo trên máy chủ của bạn. Turnstile hỗ trợ nhiều rendering methods bao gồm hiển thị rõ ràng và ngụ ý. Bạn cũng có thể inject Turnstile into HTML using a Cloudflare Worker nếu bạn không kiểm soát mã nguồn đăng nhập form.
Implementing Turnstile involves three steps: create a widget, add the client-side snippet to your login form, and validate the token on your server. Turnstile supports multiple rendering methods including explicit and implicit rendering. You can also inject Turnstile into HTML using a Cloudflare Worker if you do not control the login form source code.
ការអនុវត្ត Turnstile រួមបញ្ចូលទាំងបីដំណោះស្រាយ: បានបង្កើតឧបករណ៍, ការបន្ថែមឧបករណ៍កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់ Turnstile អនុញ្ញាតឱ្យមានការគាំទ្រជាច្រើន rendering methods រួមទាំងការធ្វើឱ្យប្រសើរឡើងដោយប្រសើរឡើងនិងដោយប្រសើរឡើងដោយប្រសើរឡើង។ អ្នកក៏អាច inject Turnstile into HTML using a Cloudflare Worker ប្រសិនបើអ្នកមិនគ្រប់គ្រងលេខកូដកំណត់ form ។
Turnstile được cấu hình ở cấp độ tài khoản.
Turnstile is configured at the account level.
Turnstile ត្រូវបានកំណត់នៅក្នុងកម្រិតគណនី។
  1. Trong bảng điều khiển Cloudflare, đi đến trang Turnstile.
  1. In the Cloudflare dashboard, go to the Turnstile page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Turnstile ។
  1. Chọn Add widget
  2. Điền vào các thông tin cần thiết:
  1. Select Add widget.
  2. Fill out the required information:
  1. សូមជ្រើស Add widget ។
  2. សូមបញ្ជាក់អំពីព័ត៌មានដែលត្រូវការ:
Widget name: Một tên mô tả cho widget của bạn. Hostname management: Các miền mà widget sẽ được sử dụng. * Widget mode: Chọn từ quản lý, không tương tác, hoặc vô hình.
Widget name: A descriptive name for your widget. Hostname management: Domains where the widget will be used. * Widget mode: Choose from Managed, Non-Interactive, or Invisible.
Widget name: ឈ្មោះសៀវភៅសម្រាប់ឧបករណ៍របស់អ្នក។ Hostname management: តំបន់ដែលអ្នកនឹងប្រើ widget នេះ។ * Widget mode: ជ្រើសពី Managed, Non-Interactive ឬ Invisible ។
  1. (Tùy chọn) Cài đặt Pre-clearance support cho các ứng dụng đơn trang.
  2. Chọn Create để lưu widget của bạn.
  3. Sao chép sitekey và khóa bí mật của bạn, và lưu trữ khóa bí mật một cách an toàn.
  1. (Optional) Configure Pre-clearance support for single-page applications.
  2. Select Create to save your widget.
  3. Copy your sitekey and secret key, and store the secret key securely.
  1. (គោលបំណង) ការកំណត់ Pre-clearance support សម្រាប់កម្មវិធីមួយទំព័រ។
  2. ចុច Create ដើម្បីផ្ទុក widget របស់អ្នក។
  3. ចម្លង sitekey និង key secret របស់អ្នកហើយផ្ទុក key secret ជាសុវត្ថិភាព។
Bạn cần cả sitekey và khóa bí mật trong các bước sau.
You need both the sitekey and secret key in the following steps.
អ្នកត្រូវការទាំងមូល sitekey និង secret key នៅក្នុងជំហានខាងក្រោម។
Thêm Turnstile kịch bản và container widget vào đăng nhập của bạn form. Thay thế <YOUR-SITE-KEY> bằng sitekey từ bước trước.
Add the Turnstile script and widget container to your login form. Replace <YOUR-SITE-KEY> with the sitekey from the previous step.
Add the Turnstile script and widget container to your login form ។ សូមផ្លាស់ប្តូរ <YOUR-SITE-KEY> ជាមួយនឹង sitekey ពីដំណោះស្រាយមុន។
text
<form id="login-form">

  <input type="text" id="username" placeholder="Username" required />

  <input type="password" id="password" placeholder="Password" autocomplete="off" required />

  <div class="cf-turnstile" data-sitekey="<YOUR-SITE-KEY>"></div>

  <button type="submit">Log in</button>

</form>


<script

  src="https://challenges.cloudflare.com/turnstile/v0/api.js"

  async

  defer

></script>
Widget hiển thị bên trong div và tạo ra một token khi khách truy cập vượt qua thách thức. Khi form được gửi, một token cf-turnstile-response được bao gồm trong dữ liệu form.
The widget renders inside the div and produces a token when the visitor passes the challenge. When the form is submitted, a cf-turnstile-response token is included in the form data.
The widget renders inside the div and produces a token when the visitor passes the challenge. When the form is submitted, a cf-turnstile-response token is included in the form data.
Trước khi xử lý bài gửi form, hãy gửi mã thông báo đến điểm cuối siteverify Turnstile để xác nhận vị khách đã vượt qua thách thức.
Before processing the form submission, send the token to the Turnstile siteverify endpoint to confirm the visitor passed the challenge.
មុនពេលដំណើរការការ form ការដឹកជញ្ជូន, សូមផ្ញើគណនី token ទៅ Turnstile siteverify endpoint ដើម្បីបញ្ជាក់ថាតើអ្នកទស្សនាបានបញ្ចប់ការបញ្ហា។
Máy chủ .js
server.js
ប្រព័ន្ធប្រតិបត្តិការ .js
text
const SECRET_KEY = "<YOUR-SECRET-KEY>";


async function validateTurnstile(token, remoteip) {

  try {

    const response = await fetch(

      "https://challenges.cloudflare.com/turnstile/v0/siteverify",

      {

        method: "POST",

        headers: {

          "Content-Type": "application/json",

        },

        body: JSON.stringify({

          secret: SECRET_KEY,

          response: token,

          remoteip: remoteip,

        }),

      },

    );


    const result = await response.json();

    return result;

  } catch (error) {

    console.error("Turnstile validation error:", error);

    return { success: false, "error-codes": ["internal-error"] };

  }

}
Thay thế "<YOUR-SECRET-KEY>" bằng khóa bí mật Turnstile của bạn. Điểm cuối trả về một đối tượng JSON với trường success. Chỉ xử lý form nếu success là true.
Replace "<YOUR-SECRET-KEY>" with your Turnstile secret key. The endpoint returns a JSON object with a success field. Only process the form submission if success is true.
ការផ្លាស់ប្តូរ "<YOUR-SECRET-KEY>" ដោយ Turnstile secret key របស់អ្នក។ កុំព្យូទ័រ Endpoint បានបង្ហាញនូវ JSON object ជាមួយនឹងការ success ។ ការដំណើរការ form គឺតែប្រសិនបើ success គឺ true ។
Để phát hiện gian lận bổ sung, Turnstile hỗ trợ Ephemeral IDs cung cấp một ID duy nhất, tạm thời cho mỗi phiên khách truy cập mà không lưu trữ dữ liệu cá nhân.
For additional fraud detection, Turnstile supports Ephemeral IDs that provide a unique, temporary identifier for each visitor session without storing personal data.
For additional fraud detection, Turnstile supports Ephemeral IDs that provide a unique, temporary identifier for each visitor session without storing personal data.
Để biết định dạng trả lời đầy đủ, mã lỗi và ví dụ trong các ngôn ngữ khác, hãy tham khảo Validate the token.
For the complete response format, error codes, and examples in other languages, refer to Validate the token.
ប្រសិនបើអ្នកមានតម្រូវការបញ្ចូលគ្នានៃតម្រូវការបញ្ចូលគ្នានៃការបញ្ចូលគ្នានៃតម្រូវការបញ្ចូលគ្នានៃតម្រូវការបញ្ចូលគ្នានៃតម្រូវការបញ្ចូលគ្នានៃតម្រូវការបញ្ចូលគ្នានៃតម្រូវការបញ្ចូលគ្នានៃតម្រូវការបញ្ចូលគ្នានៃតម្រូវការ Validate the token ។
Turnstile cung cấp các khóa site thử nghiệm trả về kết quả có thể dự đoán mà không cần liên hệ với Siteverify API.
Turnstile provides test site keys that return predictable results without contacting the Siteverify API.
Turnstile ផ្តល់នូវកំណត់គេហទំព័រសាកល្បងដែលបង្ហាញពីផលិតផលដែលអាចបង្ហាញបានដោយមិនទាក់ទងនឹង Siteverify API ។
  • Always passes: Sử dụng khóa trang web 1x00000000000000000000AA và khóa bí mật 1x0000000000000000000000000000000AA để mô phỏng một thách thức thành công.
  • Always blocks: Sử dụng khóa trang web 2x00000000000000000000AB và khóa bí mật 2x0000000000000000000000000000000AA để mô phỏng một thách thức thất bại.
  • Forces interactive challenge: Sử dụng phím site 3x00000000000000000000FF để kiểm tra dòng thách thức tương tác.
  • Always passes: Use site key 1x00000000000000000000AA and secret key 1x0000000000000000000000000000000AA to simulate a successful challenge.
  • Always blocks: Use site key 2x00000000000000000000AB and secret key 2x0000000000000000000000000000000AA to simulate a failed challenge.
  • Forces interactive challenge: Use site key 3x00000000000000000000FF to test the interactive challenge flow.
  • Always passes: Use site key 1x00000000000000000000AA and secret key 1x0000000000000000000000000000000AA to simulate a successful challenge.
  • Always blocks: Use site key 2x00000000000000000000AB and secret key 2x0000000000000000000000000000000AA to simulate a failed challenge.
  • Forces interactive challenge: ទាញយកគោលបំណងទីតាំង 3x00000000000000000000FF ដើម្បីធ្វើតេស្តដំណើរការជម្រើសអ៊ីនធឺណិត។
Để biết danh sách đầy đủ các phím kiểm tra và hành vi dự kiến, hãy tham khảo Test your Turnstile implementation.
For the full list of test keys and expected behaviors, refer to Test your Turnstile implementation.
សម្រាប់សៀវភៅពេញលេញនៃគោលបំណងការធ្វើតេស្តនិងការធ្វើតេស្តគោលបំណងរបស់អ្នក, សូមមើល Test your Turnstile implementation ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Giới hạn Login Endpoint Rate limit your login endpoint ទាញយក Endpoint Login របស់អ្នក

Phần «Rate limit your login endpoint» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Rate limit your login endpoint" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ទាញយក Endpoint Login របស់អ្នក» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Ví dụ sau đây tạo ra quy tắc rate limiting phát hành một Thách thức được quản lý sau khi nhiều hơn năm yêu cầu POST đến đường dẫn đăng nhập của bạn từ cùng một IP trong vòng một phút. Bắt đầu với Managed Challenge thay vì Block. Managed Challenge cho phép người dùng hợp pháp kích hoạt giới hạn để vượt qua bằng cách hoàn thành một thách thức, trong khi chặn lưu lượng truy cập tự động không thể giải quyết nó. Sau khi theo dõi Security Events để xác nhận rằng quy tắc không tạo ra dương tính giả, hãy chuyển sang Chặn. Điều chỉnh con đường (/login), ngưỡng và thời gian cho trang web của bạn.
The following example creates a rate limiting rule that issues a Managed Challenge after more than five POST requests to your login path from the same IP within one minute. Start with Managed Challenge rather than Block. Managed Challenge allows legitimate users who trigger the limit to pass by completing a challenge, while blocking automated traffic that cannot solve it. After monitoring Security Events to confirm the rule is not producing false positives, switch to Block. Adjust the path (/login), threshold, and period for your site.
ឧទាហរណ៍ខាងក្រោមបានបង្កើតច្បាប់ rate limiting ដែលធ្វើឱ្យប្រសិនបើអ្នកទទួលបានការជំរុញគ្រប់គ្រងបន្ទាប់ពីការបញ្ចូលទម្រង់ POST ច្រើនជាង 5 ទៅលើដំណើរការចុះឈ្មោះរបស់អ្នកពី IP ដូចគ្នានេះក្នុងរយៈពេល 1 នាទី។ សូមចាប់ផ្តើមជាមួយការធ្វើតេស្តគ្រប់គ្រងជាងការកាត់បន្ថយ។ ការធ្វើតេស្តគ្រប់គ្រងអនុញ្ញាតឱ្យអ្នកប្រើដែលមានប្រសិទ្ធិភាពដែលកាត់បន្ថយបញ្ហានេះដើម្បីបញ្ចប់ការធ្វើតេស្ត, ខណៈពេលដែលការកាត់បន្ថយការដឹកជញ្ជូនដោយស្វ័យប្រវត្តិដែលមិនអាចដោះស្រាយវា។ បន្ទាប់ពីការត្រួតពិនិត្យ Security Events ដើម្បីបញ្ជាក់ថាច្បាប់មិនផលិតអត្ថប្រយោជន៍ពហុ, សូមផ្លាស់ប្តូរទៅ Block. ការកំណត់ផ្លូវ (/login), កម្រិតនិងពេលវេលាសម្រាប់គេហទំព័ររបស់អ្នក។
Warning
Warning
Warning
Managed Challenge và challenge types khác đòi hỏi một phản hồi HTML để hiển thị. Chúng không hoạt động cho các câu trả lời không phải HTML như yêu cầu AJAX/XHR, phổ biến trên các điểm cuối đăng nhập sử dụng các ứng dụng một trang (SPA) hoặc xác thực dựa trên API. Nếu dòng đăng nhập của bạn sử dụng AJAX, hãy xem xét sử dụng Turnstile Pre-Clearance thay vào đó.
Managed Challenge and other challenge types require an HTML response to render. They do not work for non-HTML responses such as AJAX/XHR requests, which are common on login endpoints that use single-page applications (SPAs) or API-based authentication. If your login flow uses AJAX, consider using Turnstile Pre-Clearance instead.
ការធ្វើតេស្តគ្រប់គ្រងនិង challenge types ផ្សេងទៀតត្រូវការ HTML ឆ្លើយតបដើម្បីធ្វើតេស្ត។ ពួកគេមិនធ្វើការសម្រាប់ការឆ្លើយតបដែលមិនមាន HTML ដូចជាសំណួរ AJAX / XHR ដែលជាធម្មតានៅលើបញ្ចប់បញ្ចូលដែលប្រើកម្មវិធីមួយទំព័រ (SPAs) ឬ API-based authentication ។ ប្រសិនបើដំណោះស្រាយដំណោះស្រាយដំណោះស្រាយដំណោះស្រាយដំណោះស្រាយដំណោះស្រាយដំណោះស្រាយដំណោះស្រាយដំណោះស្រាយដំណោះស្រាយដំណោះស្រាយដំណោះស្រាយដំណោះស្រាយ Turnstile Pre-Clearance ។
  1. Trong bảng điều khiển Cloudflare, đi đến trang Security rules.
  1. In the Cloudflare dashboard, go to the Security rules page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Security rules ។
  1. Chọn Create rule và chọn Rate limiting rules.
  2. Nhập tên cho quy tắc (ví dụ: "Rate limit login endpoint").
  3. Trong When incoming requests match, chọn Edit expression và nhập: http.host eq "example.com" and http.request.uri.path eq "/login" and http.request.method eq "POST"
  1. Select Create rule and choose Rate limiting rules.
  2. Enter a name for the rule (for example, "Rate limit login endpoint").
  3. Under When incoming requests match, select Edit expression and enter: http.host eq "example.com" and http.request.uri.path eq "/login" and http.request.method eq "POST"
  1. ចុច Create rule ហើយចុច Rate limiting rules ។
  2. បញ្ចូលឈ្មោះសម្រាប់ច្បាប់ (ដូចជា "Rate limit login endpoint") ។
  3. នៅក្រោម When incoming requests match, ជ្រើស Edit expression និងចុះឈ្មោះ: http.host eq "example.com" and http.request.uri.path eq "/login" and http.request.method eq "POST"
Thay thế \example.com\ bằng tên miền của bạn và \/login\ bằng đường dẫn điểm cuối đăng nhập của bạn.
Replace \example.com\ with your domain and \/login\ with your login endpoint path.
ការផ្លាស់ប្តូរ \example.com\ ជាមួយនឹងតំបន់បណ្ដាញរបស់អ្នកនិង \/login\ ជាមួយនឹងដំណោះស្រាយ endpoint login របស់អ្នក។
  1. Trong With the same characteristics, hãy xác minh rằng IP đã được chọn. Trên các gói miễn phí, điều này được đặt trước thành IP.
  2. Trong When rate exceeds, nhập 5 cho Requests và chọn một giá trị cho Period. Trên gói miễn phí, hãy chọn 10 seconds. Pro và trên các kế hoạch cung cấp thời gian bổ sung. Đối với các giá trị có sẵn theo kế hoạch, hãy tham khảo Rate limiting parameters.
  3. Trong Then take action, chọn action từ thả xuống Choose action. Trên gói miễn phí, hãy chọn Block. Trên Pro và trên, Managed Challenge được khuyến cáo vì nó cho phép người dùng hợp pháp kích hoạt giới hạn để vượt qua bằng cách hoàn thành một thách thức.
  4. Trong For duration, chọn một thời gian cho action. Trên gói miễn phí, hãy chọn 10 seconds. Pro và trên các kế hoạch cung cấp thời gian dài hơn. Đây là thời gian action áp dụng sau khi giới hạn tỷ lệ được kích hoạt.
  5. Chọn Deploy
  1. Under With the same characteristics, verify that IP is selected. On Free plans, this is preset to IP.
  2. Under When rate exceeds, enter 5 for Requests and select a value for Period. On Free plans, select 10 seconds. Pro and above plans offer additional periods. For available values by plan, refer to Rate limiting parameters.
  3. Under Then take action, select an action from the Choose action dropdown. On Free plans, select Block. On Pro and above, Managed Challenge is recommended because it allows legitimate users who trigger the limit to pass by completing a challenge.
  4. Under For duration, select a duration for the action. On Free plans, select 10 seconds. Pro and above plans offer longer durations. This is how long the action applies after the rate limit is triggered.
  5. Select Deploy.
  1. នៅក្រោម With the same characteristics សូមបញ្ជាក់ថា IP ត្រូវបានជ្រើសរើស។ នៅលើគម្រោងដោយឥតគិតថ្លៃវាត្រូវបានកំណត់ទៅ IP។
  2. នៅក្រោម When rate exceeds, ទាញយក 5 សម្រាប់ Requests ហើយជ្រើសរើសតម្លៃសម្រាប់ Period ។ នៅលើគម្រោងដោយឥតគិតថ្លៃចុច 10 seconds ។ គម្រោង pro និង above បានផ្តល់ជូននូវពេលវេលាបន្ថែមទៀត។ សម្រាប់គុណសម្បត្តិដែលអាចរកបានដោយគំនិត, សូមមើល Rate limiting parameters ។
  3. នៅក្រោម Then take action, ជ្រើស action ពីការបង្វិល Choose action ។ នៅលើគម្រោងដោយឥតគិតថ្លៃចុច Block ។ នៅលើអ្នកជំនាញនិងខ្ពស់ជាងនេះ, Managed Challenge ត្រូវបានផ្តល់អនុសាសន៍ដោយសារតែវាអាចអនុញ្ញាតឱ្យអ្នកប្រើដែលមានសុវត្ថិភាពដែលកាត់បន្ថយការកាត់បន្ថយដោយបញ្ចប់ការជោគជ័យ។
  4. Under For duration, select a duration for the action. On Free plans, select 10 seconds. Pro and above plans offer longer durations. This is how long the action applies after the rate limit is triggered.
  5. សូមជ្រើស Deploy ។
(Tùy chọn) Để chỉ đếm các nỗ lực đăng nhập thất bại thay vì tất cả các yêu cầu khớp, người dùng Business plan và trên có thể thêm một biểu thức đếm riêng biệt dưới Increment counter when:
(Optional) To count only failed login attempts instead of all matching requests, Business plan and above users can add a separate counting expression under Increment counter when:
(Optional) To count only failed login attempts instead of all matching requests, Business plan and above users can add a separate counting expression under Increment counter when:
text
http.request.uri.path eq "/login" and http.request.method eq "POST" and http.response.code in {401 403}
Điều này đếm các yêu cầu dựa trên mã trạng thái phản hồi. Các đăng nhập thành công (200) không tăng số lượng.
This counts requests based on the response status code. Successful logins (200) do not increment the counter.
វាត្រូវបានកំណត់ដោយផ្អែកលើលេខកូដសកម្មភាពការឆ្លើយតប។ ការចូលរួមដែលបានជោគជ័យ (200) មិនបង្កើនការកាត់បន្ថយ។
Tiến bộ Rate Limiting (Enterprise)
Advanced Rate Limiting (Enterprise)
កម្រិតខ្ពស់ Rate Limiting (អាជីវកម្ម)
Khách hàng doanh nghiệp với Advanced Rate Limiting có thể giới hạn xếp hạng theo đặc điểm ngoài địa chỉ IP, điều này hữu ích khi kẻ tấn công phân phối các nỗ lực trên nhiều địa chỉ IP. Để biết các tính năng sẵn có và khả năng sẵn có của gói, hãy tham khảo Rate limiting parameters.
Enterprise customers with Advanced Rate Limiting can rate limit by characteristics beyond IP address, which is useful when attackers distribute attempts across many IP addresses. For available characteristics and plan availability, refer to Rate limiting parameters.
អ្នកអតិថិជនអាជីវកម្មដែលមាន Advanced Rate Limiting អាចកំណត់តម្លៃដោយលក្ខណៈផ្សេងទៀតជាងអាសយដ្ឋាន IP ដែលមានប្រសិទ្ធិភាពនៅពេលដែលអ្នកប្រឆាំងនឹងការផ្លាស់ប្តូរការធ្វើតេស្តនៅលើអាសយដ្ឋាន IP ច្រើន។ សម្រាប់លក្ខណៈពិសេសដែលអាចរកបាននិងលក្ខណៈពិសេសដែលអាចរកបាន, សូមមើល Rate limiting parameters ។
Đối với các trang web trải nghiệm các chiến dịch nạp thông tin liên tục, hãy xem xét triển khai nhiều quy tắc rate limiting với mức độ nghiêm trọng ngày càng tăng. Trang Rate limiting best practices mô tả một mô hình hình phạt leo thang sử dụng ba quy tắc: một quy tắc cửa sổ ngắn cho các vụ nổ nhanh, một quy tắc cửa sổ trung bình cho các cuộc tấn công phân tán chậm hơn và một quy tắc cửa sổ dài ngăn chặn những kẻ tấn công dai dẳng từ toàn bộ miền. Các biểu thức đếm sử dụng mã trạng thái phản hồi, vì vậy các đăng nhập thành công không đếm chống lại giới hạn. Hãy tham khảo trang thực hành tốt nhất cho ngưỡng được đề xuất và phác thảo biểu thức.
For sites that experience sustained credential stuffing campaigns, consider deploying multiple rate limiting rules with increasing severity. The Rate limiting best practices page describes an escalating penalty pattern that uses three rules: a short-window rule for quick bursts, a medium-window rule for slower distributed attacks, and a long-window rule that blocks persistent attackers from the entire domain. The counting expressions use response status codes, so successful logins do not count against the limit. Refer to the best practices page for the recommended thresholds and expression syntax.
សម្រាប់គេហទំព័រដែលមានបទពិសោធន៍នៃការបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តាល។ ទំព័រ Rate limiting best practices បានពិពណ៌នាអំពីគំរូការកាត់បន្ថយការកាត់បន្ថយដែលប្រើបីច្បាប់: គោលដៅកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយកាត់បន្ថយក ការគណនានៃការគណនានៃការគណនានៃការគណនានៃការគណនានៃការគណនានៃការគណនានៃការគណនានៃការគណនានៃការគណនានៃការគណនានៃការគណនានៃការគណនានៃការគណនានៃការគណនានៃការគណនានៃការគណនានៃការគាំទ្រ។ សូមពិនិត្យមើលទំព័រគោលបំណងល្អបំផុតសម្រាប់ទំហំទំហំគោលបំណងដែលផ្តល់អនុសាសន៍និងសម្ភារៈសម្ភារៈ។
Các quy tắc ví dụ này yêu cầu một kế hoạch kinh doanh hoặc cao hơn vì chúng sử dụng các biểu thức đếm tham chiếu đến mã phản hồi HTTP.
These example rules require a Business plan or above because they use counting expressions that reference HTTP response codes.
លក្ខខណ្ឌឧទាហរណ៍នេះត្រូវការរចនាសម្ព័ន្ធអាជីវកម្មឬខ្ពស់ជាងនេះដោយសារតែពួកគេប្រើការគណនាសម្ព័ន្ធគណនាសម្ព័ន្ធដែលផ្លាស់ប្តូរ HTTP កូដឆ្លើយតប។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Thêm các quy tắc bảo mật ứng dụng cho các mẫu đăng nhập đáng ngờ Add Application Security rules for suspicious login patterns លក្ខខណ្ឌសុវត្ថិភាពកម្មវិធីសម្រាប់គំរូការចុះឈ្មោះគួរឱ្យចាប់អារម្មណ៍

Phần «Thêm ứng dụng Security rules for suspicious login patterns» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Add Application Security rules for suspicious login patterns" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «លក្ខខណ្ឌសុវត្ថិភាពកម្មវិធីសម្រាប់គំរូការចុះឈ្មោះគួរឱ្យចាប់អារម្មណ៍» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Ứng dụng bảo mật custom rules và traffic detections cung cấp cho bạn tín hiệu bổ sung vượt quá tỷ lệ yêu cầu để xác định và hành động đối với lưu lượng truy cập đăng nhập đáng ngờ. Phát hiện chứa đầy đủ các trường yêu cầu (chẳng hạn như trạng thái xác thực bị rò rỉ và điểm số bot) mà quy tắc tùy chỉnh của bạn sau đó có thể tham chiếu.
Application Security custom rules and traffic detections give you additional signals beyond request rate to identify and act on suspicious login traffic. Detections populate request fields (such as leaked credential status and bot score) that your custom rules can then reference.
ការសុវត្ថិភាពកម្មវិធី custom rules និង traffic detections អនុញ្ញាតឱ្យអ្នកនូវសញ្ញាបនប័ត្របន្ថែមទៀតជាងទំហំសំណួរដើម្បីរកឃើញនិងដោះស្រាយលើការចូលដំណើរការដែលគួរឱ្យចាប់អារម្មណ៍។ ការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយការកាត់បន្ថយ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Turn on leaked credentials phát hiện Turn on leaked credentials detection ចុចលើការរកឃើញ credentials leaked

Phần «Turn on leaked credentials detection» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Turn on leaked credentials detection" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ចុចលើការរកឃើញ credentials leaked» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Phát hiện thông tin xác thực bị rò rỉ quét các yêu cầu đăng nhập đến cho tên người dùng và mật khẩu xuất hiện trong cơ sở dữ liệu vi phạm dữ liệu được biết đến. Cloudflare hash credentials trước khi so sánh và không lưu trữ mật khẩu văn bản đơn. Khi một trận đấu được tìm thấy, phát hiện chứa các trường bạn có thể sử dụng trong các quy tắc tùy chỉnh và rate limiting quy tắc.
Leaked credentials detection scans incoming login requests for usernames and passwords that appear in known data breach databases. Cloudflare hashes credentials before comparison and does not store plaintext passwords. When a match is found, the detection populates fields you can use in custom rules and rate limiting rules.
ការកាត់បន្ថយវិញ្ញាបនប័ត្របានកាត់បន្ថយវិញ្ញាបនប័ត្រក្នុងការស្វែងរកការទូទាត់ចូលទៅសម្រាប់ឈ្មោះអ្នកប្រើប្រាស់និងសញ្ញាបនប័ត្រដែលបានបង្ហាញនៅក្នុងមូលដ្ឋានទិន្នន័យការទាត់បន្ថយទិន្នន័យដែលបានដឹង។ Cloudflare កាត់បន្ថយវិញ្ញាបនប័ត្រមុនពេលប្រៀបធៀបនិងមិនរក្សាទុកសញ្ញាបនប័ត្រស្លាក។ នៅពេលដែលការត្រួតពិនិត្យត្រូវបានរកឃើញ, ការត្រួតពិនិត្យបានកំទូលាយបណ្តាញដែលអ្នកអាចប្រើនៅក្នុងការត្រួតពិនិត្យដោយផ្ទាល់និង rate limiting ។
Trường cf.waf.credential<em>check.password</em>leaked có sẵn trên tất cả các kế hoạch.
The cf.waf.credential<em>check.password</em>leaked field is available on all plans.
ស្លាក cf.waf.credential<em>check.password</em>leaked គឺអាចរកបាននៅលើគម្រោងទាំងអស់។
Trường cf.waf.credential<em>check.username</em>and<em>password</em>leaked yêu cầu gói Pro hoặc cao hơn.
The cf.waf.credential<em>check.username</em>and<em>password</em>leaked field requires a Pro plan or above.
កន្លែង cf.waf.credential<em>check.username</em>and<em>password</em>leaked ដែលត្រូវការគណនី Pro ឬច្រើនជាងនេះ។
Trên các gói miễn phí, việc phát hiện thông tin bị rò rỉ được bật theo mặc định và không cần action. Trên các gói trả tiền, bạn có thể bật phát hiện trong bảng điều khiển Cloudflare, thông qua API, hoặc bằng cách sử dụng Terraform.
On Free plans, the leaked credentials detection is enabled by default, and no action is required. On paid plans, you can turn on the detection in the Cloudflare dashboard, via API, or using Terraform.
នៅលើគម្រោងដោយឥតគិតថ្លៃការរកឃើញគោលបំណងដែលបានបំបែកត្រូវបានអនុញ្ញាតដោយទូទៅហើយគ្មាន action ដែលត្រូវការ។ នៅលើទូទាត់ទូទាត់អ្នកអាចផ្លាស់ប្តូរការរកឃើញនៅក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare ដោយប្រើ API ឬដោយប្រើ Terraform ។
  1. Trong bảng điều khiển Cloudflare, đi đến trang Bảo mật Settings.
  1. In the Cloudflare dashboard, go to the Security Settings page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Security Settings ។
  1. (Tùy chọn) Filter by Detection tools.
  2. Nhấp vào Leaked credential detection
  1. (Optional) Filter by Detection tools.
  2. Turn on Leaked credential detection.
  1. (តម្រូវការ) Filter by Detection tools.
  2. សូមចុច Leaked credential detection ។
  1. Đăng nhập vào Cloudflare dashboard ↗ và chọn tài khoản và tên miền của bạn.
  2. Đi đến Security \> Settings.
  3. Trong Incoming traffic detections, hãy bật Leaked credentials.
  1. Log in to the Cloudflare dashboard ↗, and select your account and domain.
  2. Go to Security \> Settings.
  3. Under Incoming traffic detections, turn on Leaked credentials.
  1. ចុច Cloudflare dashboard ↗ ហើយជ្រើសគណនីរបស់អ្នកនិងតំបន់បណ្ដាញរបស់អ្នក។
  2. ចុចទៅ Security \> Settings ។
  3. នៅក្រោម Incoming traffic detections ចុច Leaked credentials ។
Sử dụng yêu cầu POST tương tự như sau:
Use a POST request similar to the following:
ប្រើការ POST ដូចខាងក្រោមនេះ:
Yêu cầu quyền token API
Required API token permissions
តម្រូវការ API សមត្ថភាព token
Ít nhất một trong các token permissions sau đây là cần thiết:
At least one of the following token permissionsis required:
មានតម្រូវការមួយចំនួននៃ token permissions ដូចខាងក្រោម:
  • Zone WAF Write
  • Account WAF Write
  • Zone WAF Write
  • Account WAF Write
  • Zone WAF Write
  • Account WAF Write
Set Leaked Credential Checks Status (Tình trạng kiểm tra xác thực bị rò rỉ)
Set Leaked Credential Checks Status
ការត្រួតពិនិត្យការត្រួតពិនិត្យការត្រួតពិនិត្យកំណត់
text
curl "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/leaked-credential-checks" \

  --request POST \

  --header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \

  --json '{

    "enabled": true

  }'
Sử dụng tài nguyên cloudflare<em>leaked</em>credential_check để cho phép phát hiện thông tin xác thực bị rò rỉ cho một khu vực. Ví dụ:
Use the cloudflare<em>leaked</em>credential_check resource to enable leaked credentials detection for a zone. For example:
ប្រើថ្នាំ cloudflare<em>leaked</em>credential_check ដើម្បីអនុញ្ញាតការកាត់បន្ថយវិញ្ញាបនប័ត្រសម្រាប់តំបន់។ ឧទាហរណ៍ :
text
resource "cloudflare_leaked_credential_check" "zone_lcc_example" {

  zone_id = var.cloudflare_zone_id

  enabled = true

}
Sau khi bật phát hiện, máy chủ nguồn của bạn có thể nhận được trạng thái xác thực bị rò rỉ thông qua tiêu đề yêu cầu Exposed-Credential-Check. Để chuyển tiêu đề này, hãy bật Add leaked credentials checks header quản lý chuyển đổi. origin can sau đó kích hoạt đặt lại mật khẩu cho người dùng bị ảnh hưởng.
After turning on the detection, your origin server can receive leaked credential status via the Exposed-Credential-Check request header. To forward this header, turn on the Add leaked credentials checks header managed transform. Your origin can then trigger a password reset for affected users.
បន្ទាប់ពីទាញយកការសាកល្បងអ្នកអាចទទួលបានស្ថានភាពសមត្ថភាពដែលបានបំពាក់តាមរយៈ Exposed-Credential-Check request header ។ ប្រសិនបើអ្នកចង់ផ្លាស់ប្តូរកំណត់ Add leaked credentials checks header ។ ទូរស័ព្ទរបស់អ្នក origin can បន្ទាប់មកកាត់បន្ថយកំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់។
Enterprise: Tùy chỉnh vị trí phát hiện
Enterprise: Custom detection locations
Enterprise: ឧបករណ៍រកឃើញផ្ទាល់ខ្លួន
Nếu ứng dụng của bạn sử dụng tên trường xác thực không chuẩn, khách hàng Enterprise có thể cấu hình custom detection locations để cho biết Cloudflare nơi tìm tên người dùng và mật khẩu trong yêu cầu HTTP.
If your application uses non-standard credential field names, Enterprise customers can configure custom detection locations to tell Cloudflare where to find usernames and passwords in HTTP requests.
If your application uses non-standard credential field names, Enterprise customers can configure custom detection locations to tell Cloudflare where to find usernames and passwords in HTTP requests.

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Tạo một quy tắc bỏ qua cho lưu lượng truy cập tự động hợp pháp Create a skip rule for legitimate automated traffic ការបង្កើតច្បាប់បង្វិលសម្រាប់ការដឹកជញ្ជូនដោយស្វ័យប្រវត្តិដោយត្រឹមត្រូវ

Phần «Tạo skip rule for legitimate automated traffic» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Create a skip rule for legitimate automated traffic" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការបង្កើតច្បាប់បង្វិលសម្រាប់ការដឹកជញ្ជូនដោយស្វ័យប្រវត្តិដោយត្រឹមត្រូវ» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Trước khi triển khai các quy tắc thách thức hoặc chặn lưu lượng truy cập đăng nhập, hãy tạo một quy tắc bỏ qua miễn lưu lượng truy cập tự động hợp pháp đã biết. Điều này ngăn chặn các công cụ giám sát, kiểm tra sức khỏe và hội nhập đối tác của bạn bị chặn bởi các quy tắc sau đây.
Before deploying rules that challenge or block login traffic, create a skip rule that exempts known legitimate automated traffic. This prevents your monitoring tools, health checks, and partner integrations from being blocked by the rules that follow.
មុនពេលធ្វើការដំឡើងច្បាប់ដែលជំរុញឬកាត់បន្ថយការធ្វើតេស្តការធ្វើតេស្តធ្វើតេស្តធ្វើតេស្តដែលបាត់បន្ថយការធ្វើតេស្តការធ្វើតេស្តដោយស្វ័យប្រវត្តិដែលមានលក្ខណៈពិសេស។ នេះធ្វើឱ្យប្រសិនបើឧបករណ៍ត្រួតពិនិត្យរបស់អ្នក, ការត្រួតពិនិត្យសុខភាពនិងការរួមបញ្ចូលគ្នានៃដៃគូរបស់អ្នកមិនត្រូវបានកាត់បន្ថយដោយច្បាប់ដែលបន្ទាប់មក។
  1. Trong bảng điều khiển Cloudflare, đi đến trang Security rules.
  1. In the Cloudflare dashboard, go to the Security rules page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Security rules ។
  1. Chọn Create rule và chọn Custom rules.
  2. Nhập một tên cho quy tắc (ví dụ, "Skip login rules for known clients").
  3. Chọn Edit expression và nhập một biểu thức phù hợp với lưu lượng truy cập tự động hợp pháp của bạn. Ví dụ, để bỏ qua các bot đã được xác minh và một dịch vụ giám sát cụ thể IP:
  1. Select Create rule and choose Custom rules.
  2. Enter a name for the rule (for example, "Skip login rules for known clients").
  3. Select Edit expression and enter an expression that matches your legitimate automated traffic. For example, to skip verified bots and a specific monitoring service IP:
  1. ចុច Create rule ហើយចុច Custom rules ។
  2. បញ្ចូលឈ្មោះសម្រាប់ធម្មតា (ដូចជា "ធម្មតាសម្រាប់អតិថិជនដែលមានឈ្មោះ") ។
  3. ជ្រើស Edit expression និងបញ្ចូលការបង្ហាញដែលសមរម្យជាមួយការដឹកជញ្ជូនដោយស្វ័យប្រវត្តិរបស់អ្នក។ ឧទាហរណ៍ដើម្បីបាត់បន្ថយប្លុកដែលបានត្រួតពិនិត្យនិងសេវាកម្មត្រួតពិនិត្យពិសេស IP:
text
(cf.client.bot) or (ip.src eq 198.51.100.1)
Thay thế 198.51.100.1 bằng địa chỉ IP của dịch vụ giám sát của bạn. Thêm các điều kiện bổ sung cho các khách hàng đã biết khác.
Replace 198.51.100.1 with the IP address of your monitoring service. Add additional conditions for other known clients.
ការផ្លាស់ប្តូរ 198.51.100.1 ជាមួយ IP អាសយដ្ឋាននៃសេវាកម្មត្រួតពិនិត្យរបស់អ្នក។ លក្ខខណ្ឌបន្ថែមទៀតសម្រាប់អតិថិជនដែលមានឈ្មោះផ្សេងទៀត។
  1. Trong Then take action, hãy chọn Skip. Trong WAF components to skip, chọn các thành phần áp dụng cho các quy tắc bảo vệ đăng nhập của bạn (ví dụ: All remaining custom rules và All rate limiting rules).
  2. Chọn Deploy
  3. Dưới Place at, đặt quy tắc trên quy tắc chặn và thách thức của bạn. Các quy tắc tùy chỉnh được thực hiện theo thứ tự, vì vậy quy tắc bỏ lỡ phải đến trước.
  1. Under Then take action, select Skip. Under WAF components to skip, select the components that apply to your login protection rules (for example, All remaining custom rules and All rate limiting rules).
  2. Select Deploy.
  3. Under Place at, place the rule above your blocking and challenge rules. Custom rules execute in order, so the skip rule must come first.
  1. នៅក្រោម Then take action សូមជ្រើស Skip ។ នៅក្រោម WAF components to skip, ជ្រើសផ្នែកដែលអនុវត្តសម្រាប់ច្បាប់ការពារការចុះឈ្មោះរបស់អ្នក (ដូចជា All remaining custom rules និង All rate limiting rules) ។
  2. សូមជ្រើស Deploy ។
  3. ក្នុងតម្រូវការ Place at, ទាញយកស្ដង់ដារនៅលើការកាត់បន្ថយនិងការជួញដូររបស់អ្នក។ លក្ខខណ្ឌលក្ខខណ្ឌលក្ខខណ្ឌលក្ខខណ្ឌលក្ខខណ្ឌលក្ខខណ្ឌ លក្ខខណ្ឌលក្ខខណ្ឌ លក្ខខណ្ឌ លក្ខខណ្ឌ លក្ខខណ្ឌ លក្ខខណ្ឌ លក្ខខណ្ឌ លក្ខខណ្ឌ
Để biết thêm thông tin về Skip action và các tùy chọn skip có sẵn, hãy tham khảo Skip action.
For more information about the Skip action and available skip options, refer to Skip action.
សម្រាប់ព័ត៌មានបន្ថែមអំពី Skip action និងតម្រូវការ skip ដែលអាចរកបានសូមមើល Skip action ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Chặn yêu cầu với các tiêu đề đáng ngờ Block requests with suspicious headers ប្លុកទម្រង់ជាមួយនឹង headers រីករាយ

Phần «Block requests với suspicious headers» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Block requests with suspicious headers" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ប្លុកទម្រង់ជាមួយនឹង headers រីករាយ» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Các công cụ điền thông tin thường gửi yêu cầu mà không có tiêu đề trình duyệt tiêu chuẩn hoặc với các mẫu User-Agent xấu. Tạo một quy tắc tùy chỉnh phát hành một Thách thức được quản lý cho các yêu cầu POST đến con đường đăng nhập của bạn nơi User-Agent trống. Điều này nhắm mục tiêu các yêu cầu POST trực tiếp từ các công cụ như curl, python-requests hoặc undici không đặt tiêu đề User-Agent.
Credential stuffing tools often send requests without standard browser headers or with known-bad User-Agent patterns. Create a custom rule that issues a Managed Challenge for POST requests to your login path where the User-Agent is empty. This targets direct POST requests from tools like curl, python-requests, or undici that do not set a User-Agent header.
ឧបករណ៍ដំឡើងអត្ថប្រយោជន៍ជាទូទៅផ្ញើអត្ថប្រយោជន៍ដោយគ្មានកំណត់ហេតុបណ្ដាញធម្មតាឬជាមួយនឹងគំរូ User-Agent ដែលគួរឱ្យចាប់អារម្មណ៍។ បានបង្កើតច្បាប់ផ្ទាល់ខ្លួនដែលធ្វើឱ្យការបញ្ជូនជម្រើសគ្រប់គ្រងសម្រាប់សំណួរ POST ទៅជម្រើសការចូលរួមរបស់អ្នកដែលអេក្រង់អ្នកប្រើប្រាស់គឺគ្មាន។ វាត្រូវបានគោលបំណងដោយផ្ទាល់ទៅនឹងសំណួរ POST ពីឧបករណ៍ដូចជា curl, python-requests ឬ undici ដែលមិនបានកំណត់កំណត់កំណត់ User-Agent ។
Các quy tắc quản lý bảo mật ứng dụng bao gồm các quy tắc cho user-agents trống, nhưng các quy tắc này bị vô hiệu hóa theo mặc định và áp dụng rộng rãi. Quy tắc tùy chỉnh bên dưới nhắm mục tiêu con đường đăng nhập của bạn cụ thể.
The Application Security Managed Ruleset includes rules for empty user-agents, but these are disabled by default and apply broadly. The custom rule below targets your login path specifically.
គោលនយោបាយគ្រប់គ្រងសុវត្ថិភាពកម្មវិធីរួមបញ្ចូលគ្នានៃគោលនយោបាយសម្រាប់អេក្រង់អ្នកប្រើគ្មានដំណោះស្រាយប៉ុន្តែគោលនយោបាយនេះត្រូវបានគ្មានដំណោះស្រាយដោយទូទៅហើយត្រូវបានអនុវត្តយ៉ាងទូលំទូលាយ។ គោលបំណងផ្ទាល់ខ្លួននៅក្រោមនេះជាតម្រូវការសម្រាប់ដំណើរការ login របស់អ្នក។
  1. Trong bảng điều khiển Cloudflare, đi đến trang Security rules.
  1. In the Cloudflare dashboard, go to the Security rules page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Security rules ។
  1. Chọn Create rule và chọn Custom rules.
  2. Nhập tên cho quy tắc (ví dụ: "Challenge empty UA on login").
  3. Chọn Edit expression và nhập:
  1. Select Create rule and choose Custom rules.
  2. Enter a name for the rule (for example, "Challenge empty UA on login").
  3. Select Edit expression and enter:
  1. ចុច Create rule ហើយចុច Custom rules ។
  2. ទោះជាយ៉ាងណាក៏ដោយអ្នកគួរតែចូលទៅក្នុងកម្មវិធីរបស់អ្នកដូចជា "Challenge empty UA on login" ។
  3. សូមជ្រើស Edit expression និងចូលទៅក្នុង:
text
(http.request.uri.path eq "/login" and http.request.method eq "POST" and len(http.user_agent) eq 0)
Thay thế /login bằng đường dẫn điểm cuối đăng nhập của bạn.
Replace /login with your login endpoint path.
សូមផ្លាស់ប្តូរ /login ជាមួយនឹងដំណើរ endpoint login របស់អ្នក។
  1. Trong Then take action, chọn Challenge quản lý.
  2. Chọn Deploy
  1. Under Then take action, select Managed Challenge.
  2. Select Deploy.
  1. នៅក្រោម Then take action, ជ្រើសរើស Managed Challenge ។
  2. សូមជ្រើស Deploy ។

Tạo quy tắc rate limiting với thông tin xác thực bị rò rỉ Create a rate limiting rule with leaked credentials ការបង្កើតច្បាប់ rate limiting ជាមួយនឹងវិញ្ញាបនប័ត្របញ្ចូល

Phần «Tạo rate limiting rule với leaked credentials» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Create a rate limiting rule with leaked credentials" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការបង្កើតច្បាប់ rate limiting ជាមួយនឹងវិញ្ញាបនប័ត្របញ្ចូល» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Kết hợp rate limiting với phát hiện thông tin xác thực bị rò rỉ để ngăn chặn các nỗ lực đăng nhập sử dụng mật khẩu đã bị xâm phạm. Quy tắc này phát hành Thách thức được quản lý khi cùng một IP gửi nhiều hơn ba yêu cầu với mật khẩu bị rò rỉ trong vòng một phút.
Combine rate limiting with leaked credentials detection to throttle login attempts that use known-compromised passwords. This rule issues a Managed Challenge when the same IP sends more than three requests with leaked passwords within one minute.
ការរួមបញ្ចូល rate limiting ជាមួយនឹងការកាត់បន្ថយវិញ្ញាបនប័ត្រដែលបានបាត់បន្ថយដើម្បីកាត់បន្ថយការជួបប្រជុំដែលប្រើកំណត់ហេតុបណ្ដាញដែលបានបាត់បន្ថយ។ គោលដៅនេះធ្វើឱ្យប្រសិនបើ IP អាចធ្វើឱ្យប្រសិនបើមានតម្រូវការច្រើនជាងបីជាមួយនឹងគោលដៅដែលបានបាត់បង់ក្នុងរយៈពេល 1 នាទី។
  1. Trên trang Security rules, chọn Create rule và chọn Rate limiting rules.
  1. On the Security rules page, select Create rule and choose Rate limiting rules.
  1. នៅលើទំព័រ Security rules ជ្រើស Create rule ហើយជ្រើស Rate limiting rules ។
  1. Nhập tên cho quy tắc (ví dụ: "Rate limit leaked credentials").
  2. Dưới When incoming requests match, hãy nhập biểu thức sau:
  1. Enter a name for the rule (for example, "Rate limit leaked credentials").
  2. Under When incoming requests match, enter the following expression:
  1. បញ្ចូលឈ្មោះសម្រាប់ច្បាប់ (ដូចជា "Rate limit leaked credentials") ។
  2. ក្នុងតម្រូវការ When incoming requests match, សូមបញ្ចូលការបង្ហាញដូចខាងក្រោម:
text
http.request.uri.path eq "/login" and http.request.method eq "POST" and cf.waf.credential_check.password_leaked
Thay thế /login bằng đường dẫn điểm cuối đăng nhập của bạn.
Replace /login with your login endpoint path.
សូមផ្លាស់ប្តូរ /login ជាមួយនឹងដំណើរ endpoint login របស់អ្នក។
  1. Trong With the same characteristics, hãy xác minh rằng IP đã được chọn. Trên các gói miễn phí, điều này được đặt trước thành IP.
  2. Trong When rate exceeds, nhập 3 cho Requests và chọn một giá trị cho Period. Trên gói miễn phí, hãy chọn 10 seconds.
  3. Trong Then take action, hãy chọn action. Trên gói miễn phí, hãy chọn Block. Trên Pro và cao hơn, Managed Challenge được khuyến khích.
  4. Trong For duration, chọn một thời gian cho action. Trên gói miễn phí, hãy chọn 10 seconds.
  5. Chọn Deploy
  1. Under With the same characteristics, verify that IP is selected. On Free plans, this is preset to IP.
  2. Under When rate exceeds, enter 3 for Requests and select a value for Period. On Free plans, select 10 seconds.
  3. Under Then take action, select an action. On Free plans, select Block. On Pro and above, Managed Challenge is recommended.
  4. Under For duration, select a duration for the action. On Free plans, select 10 seconds.
  5. Select Deploy.
  1. នៅក្រោម With the same characteristics សូមបញ្ជាក់ថា IP ត្រូវបានជ្រើសរើស។ នៅលើគម្រោងដោយឥតគិតថ្លៃវាត្រូវបានកំណត់ទៅ IP។
  2. នៅក្រោម When rate exceeds, ទាញយក 3 សម្រាប់ Requests និងជ្រើសរើសតម្លៃសម្រាប់ Period ។ នៅលើគម្រោងដោយឥតគិតថ្លៃចុច 10 seconds ។
  3. នៅក្រោម Then take action ចុច action ។ នៅលើគម្រោងដោយឥតគិតថ្លៃចុច Block ។ នៅលើប្រព័ន្ធប្រតិបត្តិការ Pro និងខ្ពស់ជាងនេះ, Managed Challenge ត្រូវបានផ្តល់អនុសាសន៍។
  4. នៅក្រោម For duration, ជ្រើសរើសអំឡុងពេលសម្រាប់ action ។ នៅលើគម្រោងដោយឥតគិតថ្លៃចុច 10 seconds ។
  5. សូមជ្រើស Deploy ។
Doanh nghiệp: Bot Management
Enterprise: Bot Management
អាជីវកម្ម: Bot Management
Khách hàng doanh nghiệp với Bot Management có thêm các công cụ bảo vệ đăng nhập:
Enterprise customers with Bot Management get additional tools for login protection:
អ្នកអតិថិជនអាជីវកម្មជាមួយ Bot Management ទទួលបានឧបករណ៍បន្ថែមទៀតសម្រាប់ការពារការចុះឈ្មោះ:
  • Custom rules with bot scores: kết hợp cf.bot_management.score với đường dẫn đăng nhập phù hợp để kiểm soát chính xác. Nhắc đến Custom rules for bot protection
  • Account takeover detections: Theo dõi khối lượng đăng nhập đáng ngờ và tỷ lệ thất bại bằng cách sử dụng ID phát hiện trong các quy tắc tùy chỉnh và quy tắc rate limiting. Nhắc đến Account takeover detections
  • Account Abuse Protection (Sớm Access): Phát hiện các mô hình gian lận tài khoản vượt ra ngoài việc điền thông tin xác thực. Nhắc đến Account Abuse Protection
  • Custom rules with bot scores: combine cf.bot_management.score with login path matching for precise control. Refer to Custom rules for bot protection.
  • Account takeover detections: monitor suspicious login volume and failure rates using detection IDs in custom rules and rate limiting rules. Refer to Account takeover detections.
  • Account Abuse Protection (Early Access): detect account fraud patterns beyond credential stuffing. Refer to Account Abuse Protection.
  • Custom rules with bot scores: ការរួមបញ្ចូល cf.bot_management.score ជាមួយនឹងការសម្តែងដំណើរការ login សម្រាប់ការគ្រប់គ្រងត្រឹមត្រូវ។ សូមអរគុណ Custom rules for bot protection
  • Account takeover detections: ការត្រួតពិនិត្យទំហំការចូលគ្នានិងទំហំការបញ្ចូលគ្នានេះមានគុណភាពដោយប្រើ IDs ការត្រួតពិនិត្យនៅក្នុងច្បាប់ផ្ទាល់ខ្លួននិងច្បាប់ rate limiting ។ សូមអរគុណ Account takeover detections
  • Account Abuse Protection (អំឡុងពេល Access): ការកាត់បន្ថយគំរូការកាត់បន្ថយគំរូការកាត់បន្ថយគំរូការកាត់បន្ថយគំរូការកាត់បន្ថយ។ សូមអរគុណ Account Abuse Protection

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Giám sát các nỗ lực thỏa hiệp đang diễn ra Monitor for ongoing compromise attempts ការត្រួតពិនិត្យសម្រាប់ការធ្វើតេស្តជួញដូរបច្ចុប្បន្ន

Phần «Monitor for ongoing compromise attempts» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Monitor for ongoing compromise attempts" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការត្រួតពិនិត្យសម្រាប់ការធ្វើតេស្តជួញដូរបច្ចុប្បន្ន» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Sau khi triển khai các quy tắc và cấu hình từ các phần trước, theo dõi điểm cuối đăng nhập của bạn để xác minh các quy tắc đang hoạt động và để phát hiện các mô hình tấn công mới.
After deploying the rules and configurations from the previous sections, monitor your login endpoint to verify the rules are working and to detect new attack patterns.
បន្ទាប់ពីការដំឡើងច្បាប់និងការកំណត់ផែនការពីផ្នែកមុនសូមត្រួតពិនិត្យបញ្ចប់ការចូលរបស់អ្នកដើម្បីត្រួតពិនិត្យពីច្បាប់ដែលធ្វើការនិងរកឃើញគំរូការជោគជ័យថ្មី។

Review sự kiện an ninh Review Security Events ការសាកល្បងសកម្មភាពសុវត្ថិភាព

Phần «Review Security Events» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Review Security Events" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការសាកល្បងសកម្មភាពសុវត្ថិភាព» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Security Events hiển thị các yêu cầu mà các sản phẩm bảo mật Cloudflare đã hành động hoặc đánh dấu, bao gồm các khối, thách thức và bỏ qua.
Security Events shows requests that Cloudflare security products acted on or flagged, including blocks, challenges, and skips.
Security Events បង្ហាញពីសំណួរដែលផលិតផលសុវត្ថិភាព Cloudflare បានអនុវត្តឬប្លុករួមបញ្ចូលទាំងការប្លុកការបំបែកនិងការបង្វិល។
  1. Trong bảng điều khiển Cloudflare, đi đến trang Analytics.
  1. In the Cloudflare dashboard, go to the Analytics page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Analytics ។
  1. Chọn tab Events
  1. Select the Events tab.
  1. សូមចុច Events ។
Xem lại Sampled logs để kiểm tra các yêu cầu riêng lẻ. Mỗi mục nhập nhật ký hiển thị action được lấy, quy tắc kích hoạt, nguồn IP, đại lý người dùng, đường dẫn URI và quốc gia. Sử dụng nút Add filter để thu hẹp kết quả bằng action, nguồn IP, ASN hoặc các trường khác.
Review the Sampled logs to inspect individual requests. Each log entry shows the action taken, the rule that triggered, the source IP, user agent, URI path, and country. Use the Add filter button to narrow results by action, source IP, ASN, or other fields.
សូមពិនិត្យមើល Sampled logs ដើម្បីពិនិត្យមើលសំណួរពិសេស។ ទិន្នន័យទាំងអស់នេះបង្ហាញនូវ action ដែលបានកាត់បន្ថយ, គោលដៅដែលបានកាត់បន្ថយ, គោលដៅ IP ដែលបានកាត់បន្ថយ, អេក្រង់អ្នកប្រើប្រាស់, ផ្លូវ URI និងប្រទេស។ ប្រើកញ្ចក់ Add filter ដើម្បីកាត់បន្ថយផលិតផលដោយ action, ទិន្នន័យ IP, ASN ឬឧបករណ៍ផ្សេងទៀត។
Tìm kiếm tích cực giả - lưu lượng truy cập hợp pháp mà các quy tắc của bạn đã thách thức hoặc chặn một cách không chính xác. Các dấu hiệu phổ biến bao gồm:
Look for false positives — legitimate traffic that your rules incorrectly challenged or blocked. Common signs include:
សូមស្វែងរកអត្ថប្រយោជន៍ស្អាត - ការដឹកជញ្ជូនស្អាតដែលគោលបំណងរបស់អ្នកមិនត្រឹមត្រូវ។ សញ្ញាបនប័ត្ររួមបញ្ចូលទាំង:
  • Yêu cầu từ các dịch vụ giám sát đã biết hoặc bộ xử lý thanh toán xuất hiện trong các sự kiện bị chặn
  • Số lượng lớn các yêu cầu thách thức từ các quốc gia nơi bạn có người dùng thực
  • Rate limiting quy tắc kích hoạt trên người dùng hợp pháp trong giao thông đỉnh
  • Requests from known monitoring services or payment processors appearing in blocked events
  • High volumes of challenged requests from countries where you have real users
  • Rate limiting rules triggering on legitimate users during peak traffic
  • ការស្វែងរកពីសេវាកម្មការត្រួតពិនិត្យដែលដឹងឬអ្នកដំណើរការទូទាត់ដែលបានបង្ហាញនៅក្នុងព្រឹត្តិការណ៍ដែលត្រូវបានកាត់បង់
  • ទំហំខ្ពស់នៃតម្រូវការសាកល្បងពីប្រទេសដែលអ្នកមានអ្នកប្រើពិតប្រាកដ
  • Rate limiting ដំណោះស្រាយដែលកាត់បន្ថយអ្នកប្រើដែលមានសុវត្ថិភាពក្នុងពេលដំណើរការខ្ពស់
Nếu bạn thấy người dùng hợp pháp bị ảnh hưởng, hãy điều chỉnh ngưỡng rate limiting của bạn hoặc thêm quy tắc bỏ qua cho các phạm vi IP cụ thể.
If you see legitimate users being affected, adjust your rate limiting thresholds or add skip rules for specific IP ranges.
ប្រសិនបើអ្នកមើលឃើញអ្នកប្រើដែលមានលក្ខណៈសម្បត្តិដែលមានសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្បត្តិសម្ប

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Thiết lập thông báo cho các sự kiện bảo mật (Business và Enterprise) Set up notifications for security event spikes (Business and Enterprise) ការបង្កើតប្រព័ន្ធប្រតិបត្តិការអ៊ីនធឺណិត (Business and Enterprise)

Phần «Thiết lập notifications for security event spikes (Business và Enterprise)» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Set up notifications for security event spikes (Business and Enterprise)" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការបង្កើតប្រព័ន្ធប្រតិបត្តិការអ៊ីនធឺណិត (Business and Enterprise)» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Thiết lập thông báo Security Events Alert để nhận cảnh báo khi âm lượng sự kiện bảo mật tăng cao, cho bạn cảnh báo sớm về một chiến dịch tấn công mới. Thông báo này nằm trong danh mục WAF của trang Notifications. Để biết hướng dẫn cài đặt, hãy tham khảo Create a notification. Khách hàng doanh nghiệp có thể sử dụng Advanced Security Events Alert để lọc nhiều hạt hơn.
Set up a Security Events Alert notification to receive alerts when security event volume spikes, giving you early warning of a new attack campaign. This notification is in the WAF category of the Notifications page. For setup instructions, refer to Create a notification. Enterprise customers can use Advanced Security Events Alert for more granular filtering.
ការបញ្ជាក់ Security Events Alert ដើម្បីទទួលបានការអនុម័តនៅពេលដែលប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើ ការអនុម័តនេះគឺនៅក្នុងប្រភេទ WAF នៃទំព័រ Notifications ។ សម្រាប់ការដំឡើងបញ្ជាក់សូមមើល Create a notification ។ អ្នកអតិថិជនអាជីវកម្មអាចប្រើ Advanced Security Events Alert សម្រាប់ការត្រួតពិនិត្យបន្ថែមទៀត។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Đánh giá mô hình lưu lượng bot (Pro và trên) Review bot traffic patterns (Pro and above) ការពិនិត្យឡើងវិញគំរូដំណើរការ bot (Pro និងខ្ពស់ជាងនេះ)

Phần «Review bot traffic patterns (Pro và above)» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Review bot traffic patterns (Pro and above)" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការពិនិត្យឡើងវិញគំរូដំណើរការ bot (Pro និងខ្ពស់ជាងនេះ)» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Phân tích lưu lượng bot cho thấy phân phối điểm số bot trên điểm cuối đăng nhập của bạn theo thời gian. Một đỉnh đột ngột trong lưu lượng truy cập có điểm số thấp (số điểm 1-29) trên con đường đăng nhập của bạn là một tín hiệu sớm của một chiến dịch điền thông tin.
Bot traffic analytics show bot score distribution on your login endpoint over time. A sudden spike in low-score traffic (scores 1-29) on your login path is an early signal of a credential stuffing campaign.
ការពន្យល់ការដឹកជញ្ជូន Bot បង្ហាញពីការផ្គត់ផ្គង់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់។ ការកើនឡើងយ៉ាងឆាប់រហ័សនៅក្នុងការដឹកជញ្ជូនដែលមានកម្រិតខ្ពស់ (កម្រិត 1-29) នៅលើដំណើរការចូលរួមរបស់អ្នកគឺជាសញ្ញាបនប័ត្រដំបូងនៃការកំណត់សញ្ញាបនប័ត្រ។
Cloudflare phân loại lưu lượng bot thành các loại dựa trên điểm số bot và trạng thái xác minh:
Cloudflare classifies bot traffic into categories based on bot scores and verification status:
Cloudflare បានប្រៀបធៀបការដឹកជញ្ជូន bot ទៅក្នុងប្រភេទដោយផ្អែកលើកម្រិត bot និងស្ថានភាពត្រួតពិនិត្យ:
  • Verified bots: Crawlers và dịch vụ mà Cloudflare đã xác nhận là hợp pháp, chẳng hạn như Googlebot, Bingbot, và giám sát thời gian hoạt động. Cloudflare duy trì verified bot list với các yêu cầu nghiêm ngặt.
  • Automated (1 điểm): Cloudflare là khá chắc chắn yêu cầu được tự động hóa.
  • Likely automated (2-29 điểm): Có thể là một bot. Thể loại này và Tự động là mục tiêu chính cho các quy tắc bảo mật, bao gồm các scraper, công cụ điền thông tin và người gửi thư rác.
  • Likely human (score 30-99): Những yêu cầu này dường như đến từ người dùng thực sự. Đừng thách thức hoặc chặn giao thông này.
  • Verified bots: Crawlers and services that Cloudflare has confirmed as legitimate, such as Googlebot, Bingbot, and uptime monitors. Cloudflare maintains a verified bot list with strict requirements.
  • Automated (score 1): Cloudflare is quite certain the request is automated.
  • Likely automated (scores 2-29): Probably a bot. This category and Automated are the primary targets for security rules, including scrapers, credential stuffing tools, and spam submitters.
  • Likely human (scores 30-99): These requests appear to come from real users. Do not challenge or block this traffic.
  • Verified bots: Crawlers និងសេវាកម្មដែល Cloudflare បានបញ្ជាក់ថាជាការពិតប្រាកដដូចជា Googlebot, Bingbot និងការត្រួតពិនិត្យអតិបរមា។ Cloudflare បានរក្សាទុក verified bot list ជាមួយនឹងតម្រូវការខ្ពស់។
  • Automated (កម្រិត 1): Cloudflare គឺជាការពិតប្រាកដយ៉ាងណាក៏ដោយតម្រូវការនេះគឺដោយស្វ័យប្រវត្តិ។
  • Likely automated (កំហុស 2-29): អាចជា bot ។ ប្រភេទនេះនិងដោយស្វ័យប្រវត្តិគឺជាតម្រូវការសំខាន់សម្រាប់ច្បាប់សុវត្ថិភាពរួមបញ្ចូលទាំង scrapers, ឧបករណ៍បំពេញវិញ្ញាបនប័ត្រនិងអ្នកដឹកជញ្ជូនអាសអាភាស។
  • Likely human (កម្រិត 30-99): ការស្វែងរកទាំងនេះបង្ហាញពីអ្នកប្រើពិតប្រាកដ។ មិនធ្វើការឬកាត់បន្ថយការដឹកជញ្ជូននេះ។
  1. Trong bảng điều khiển Cloudflare, đi đến Security \> Analytics \> Bot analysis.
  2. Xem xét phân phối lưu lượng truy cập trên các nhóm điểm số bot ở trên.
  1. In the Cloudflare dashboard, go to Security \> Analytics \> Bot analysis.
  2. Review the traffic distribution across the bot score groupings above.
  1. នៅលើប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅ Security \> Analytics \> Bot analysis ។
  2. សូមពិនិត្យមើលការផ្លាស់ប្តូរការដឹកជញ្ជូននៅទូទាំងការបណ្តុះបណ្តាលកម្រិត bot នៅខាងលើ។
Nếu bạn thấy lưu lượng truy cập tự động tiếp tục đạt đến điểm cuối đăng nhập của bạn mặc dù các quy tắc được triển khai trong hướng dẫn này, hãy xem trang Security features interoperability để xác minh rằng các quy tắc của bạn đang chạy theo thứ tự dự kiến và xem xét điều chỉnh ngưỡng.
If you see sustained automated traffic reaching your login endpoint despite the rules deployed in this guide, review the Security features interoperability page to verify your rules are executing in the expected order, and consider adjusting thresholds.
ប្រសិនបើអ្នកមើលឃើញការដឹកជញ្ជូនដោយស្វ័យប្រវត្តិដែលមានប្រសិទ្ធិភាពដើម្បីទទួលបានកំណត់បញ្ចប់ការចុះឈ្មោះរបស់អ្នកប៉ុន្តែទោះបីជាទិន្នន័យដែលត្រូវបានដំឡើងនៅក្នុងឧបករណ៍នេះ, សូមពិនិត្យមើលទំព័រ Security features interoperability ដើម្បីត្រួតពិនិត្យថាទិន្នន័យរបស់អ្នកត្រូវបានដំណើរការនៅក្នុងដំណឹងដែលគិតបានហើយគួរឱ្យកំណត់ទំហំ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Xem bản đầy đủ trên developers.cloudflare.com (ảnh, tab cấu hình). View the full guide on developers.cloudflare.com (images, config tabs). មើលមគ្គុទ្ទេសក៍ពេញលើ developers.cloudflare.com (រូបភាព, tab កំណត់)។

Tài liệu gốc ↗ Official docs ↗ ឯកសារផ្លូវការ ↗