Origin IP Exposed waf bypass
Low
Vulnerability Details
Hello team,
I have discovered that the https://52.6.254.246/ site exposed it's IP
which could allow bypassing of anti-DDoS mechanisms i.e you are using
Cloudflare for protection.
For Originate IP address which I found from https://search.censys.io/
By using these IP address as a resolver instead of the intended
addresses I'm able to access the service without going through the
WAF, thus I'm able to forward unfiltered payloads to the service, as
well as avoiding the common protections offered by Cloudflare, also
being able to perform crippling denial-of-service towards the origin.
##IP:
52.6.254.246
## Impact
Cloudflare bypasses can have a
significant impact, as any adversary is now able to communicate with
the origin server directly, enabling them to perform unfiltered
attacks (such as denial-of-service), and data retrieval.
Actions
View on HackerOneReport Stats
- Report ID: 1821085
- State: Closed
- Substate: resolved
- Upvotes: 7