Non-Cloudflare IPs allowed to access origin servers
Medium
U
Unikrn
Submitted None
Actions:
Reported by
moritz30
Vulnerability Details
Technical details and impact analysis
**Summary:** Non-Cloudflare IPs allowed to access origin servers
**Description:** Your origin servers are not blocking access from non-Cloudflare servers. This way crawlers can find your origin servers' IPs by checking random IPs until they found your origin server(s).
What makes this especially easy are tools like censys.io (which can find your origin servers).
One of the origin server IPs I found is ███████ but there were quite a few others, too.
This attack vector can be extremely bad because with the IP found out an attacker could attack the servers by DDoS or other attacks without being stopped by CloudFlare.]
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$50.00
Submitted
Weakness
Information Disclosure