Why should Cloudflare (be able to) block any request containing “boot.ini”?
I assume that it's a common test file for path traversal exploits and checking whether server process has administrator rights, and that blacklist happened to be applied inordinately, but other questions inevitably arise. What else is in the blacklist? Who controls it, and who can potentially control it? How long would it take for this bug to turn into a feature, and allow blocking "freedom", "election", "warhead", or "Assange" on a scale that is already bigger than that of Great Chinese Firewall? Also, how can one use similar innocuous user-provided plain texts to cut back-end web APIs that happen to run through Cloudflare?
Finally, has something changed recently about putting all the eggs in one basket, and expecting a free lunch?