Non-Cloudflare IPs allowed to access origin servers

Disclosed: 2018-02-07 21:43:45 By moritz30 To unikrn
Medium
Vulnerability Details
**Summary:** Non-Cloudflare IPs allowed to access origin servers **Description:** Your origin servers are not blocking access from non-Cloudflare servers. This way crawlers can find your origin servers' IPs by checking random IPs until they found your origin server(s). What makes this especially easy are tools like censys.io (which can find your origin servers). One of the origin server IPs I found is ███████ but there were quite a few others, too. This attack vector can be extremely bad because with the IP found out an attacker could attack the servers by DDoS or other attacks without being stopped by CloudFlare.]
Actions
View on HackerOne
Report Stats
  • Report ID: 255978
  • State: Closed
  • Substate: resolved
  • Upvotes: 11
Share this report