Learn about Centmin Mod LEMP Stack today
Become a Member

Cloudflare Find origin servers of websites behind by CloudFlare using Internet-wide scan data from Censys

Discussion in 'Domains, DNS, Email & SSL Certificates' started by rdan, Jan 26, 2018.

  1. rdan

    rdan Well-Known Member

    5,452
    1,418
    113
    May 25, 2014
    Ratings:
    +2,212
    Local Time:
    11:46 AM
    Mainline
    10.2
  2. eva2000

    eva2000 Administrator Staff Member

    58,893
    12,490
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,122
    Local Time:
    1:46 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    Actually that's very old news :) But guess Cloudflare ain't happy about it!

    As outlined in those articles to protect yourself you can either use firewall to block all traffic other than Cloudflare from your server or setup a Cloudflare Authenticated Origin Pull certificate on your Cloudflare Full SSL enabled site. The latter is easier to do as blocking all traffic might cause problems for other non-visitor access/communications to your server. I wrote a guide for the latter at Cloudflare - Setting Up Cloudflare Authenticated Origin Pulls Protecting IP Leaks
     
  3. BamaStangGuy

    BamaStangGuy Active Member

    669
    192
    43
    May 25, 2014
    Ratings:
    +272
    Local Time:
    10:46 PM
    We have been using Auth Orgin Pulls for quite a while now. :)
     
  4. eva2000

    eva2000 Administrator Staff Member

    58,893
    12,490
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,122
    Local Time:
    1:46 PM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+