Loading HuntDB...

Non-Cloudflare IPs allowed to access origin servers

Medium
U
Unikrn
Submitted None
Reported by moritz30

Vulnerability Details

Technical details and impact analysis

Information Disclosure
**Summary:** Non-Cloudflare IPs allowed to access origin servers **Description:** Your origin servers are not blocking access from non-Cloudflare servers. This way crawlers can find your origin servers' IPs by checking random IPs until they found your origin server(s). What makes this especially easy are tools like censys.io (which can find your origin servers). One of the origin server IPs I found is ███████ but there were quite a few others, too. This attack vector can be extremely bad because with the IP found out an attacker could attack the servers by DDoS or other attacks without being stopped by CloudFlare.]

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$50.00

Submitted

Weakness

Information Disclosure