Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I was arrested by Interpol in 2018 because of warrants issued by the NCA, DOJ, FBI, J-CAT, and several other agencies, all due to my involvement in running a DDoS-for-hire website. Honestly, anyone can bypass Cloudflare, and anyone that want to take your website down - will take it down. It's just that luckily for all of us most of the DDoS-4-hire websites are down nowadays but there are still many botnets out there that will get past basically any protection and you can get access to them for basically $5.


One minute, what? Can you elaborate on that. I have loads of questions. What exactly were you doing? What consequences did you face? How come you are talking about it?


because I'm from Serbia so I was released immediately instead of actually being jailed like my friend from Croatia ~


> anyone can bypass Cloudflare

How?


It depends how you wanna bypass it. (https://roundproxies.com/blog/bypass-cloudflare/) e.g. I found out that they track TLS, HTTP headers and Javascript JS fingerprinting. There are def some ways, personally using browsers but yeah. maybe take a look at that guide above foudn that helpful as a good starting point tho


Plenty of ways to leak the original server IP address if it isn't really well hardened against that (and most aren't).


Like? Aside from scanning DNS records (assuming the protected IP is in there somewhere) or scanning the entire IPv4 (assuming the server responds to non CloudFlare requests), I can't think of any. And both methods are simple to protect against.


Some of it is tradecraft, but have two: SSRF bugs/features and chatty email headers.


Right. Still a far cry from "anyone can bypass CloudFlare" though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: