CloudFlare Security Flaw – Origin Exposure Test
bitmitigate.com
CloudFlare Security Flaw – Origin Exposure Test
1–5 of 5 posts
Re: CloudFlare Security Flaw – Origin Exposure Test
#2Seems to be a test for the flaw. Is there any documentation surrounding the actual flaw?
Re: CloudFlare Security Flaw – Origin Exposure Test
#3Just seems to lookup subdomains in DNS that are on bypass. Checked a few domains that I have with Cloudflare and they only listed IP's that I'm explicitly bypassing Cloudflare.
Re: CloudFlare Security Flaw – Origin Exposure Test
#4This looks like a bait and switch heading to me
Re: CloudFlare Security Flaw – Origin Exposure Test
#5As other noted, this isn’t a flaw at all. https://support.cloudflare.com/hc/en-us/articles/11500368793... explains what not to do, but basically, don’t create guessable hostnames or shared services that resolve to your origin.