uncovering-cloudflare.md (14961B)
1 --- 2 title: "Uncovering CloudFlare" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/uncovering-cloudflare.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/uncovering-cloudflare.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Uncovering CloudFlare 14 15 ## Common Techniques to Uncover Cloudflare 16 17 - You can use some service that gives you the **historical DNS records** of the domain. Maybe the web page is running on an IP address used before. 18 - Same could be achieve **checking historical SSL certificates** that could be pointing to the origin IP address. 19 - Check also **DNS records of other subdomains pointing directly to IPs**, as it's possible that other subdomains are pointing to the same server (maybe to offer FTP, mail or any other service). 20 - Review all **DNS-only `A`/`AAAA`/`CNAME` siblings** and boring records such as `direct`, `origin`, `api`, `admin`, `cpanel`, `autodiscover`, `mail`, `mx`, `staging`, or forgotten IPv6-only hostnames. A single unproxied record is enough to leak the box. 21 - Audit **DNS-only TXT/SPF/MX** data and the **mail infrastructure**. If web and mail share the same machine, bounces for invalid users, SMTP banners, or `Received` headers can reveal the real IP address. 22 - If you find a **SSRF inside the web application** you can abuse it to obtain the IP address of the server. 23 - Search a unique string of the web page in browsers such as shodan (and maybe google and similar?). Maybe you can find an IP address with that content. 24 - In a similar way instead of looking for a uniq string you could search for the favicon icon with the tool: [https://github.com/karma9874/CloudFlare-IP](https://github.com/karma9874/CloudFlare-IP) or with [https://github.com/pielco11/fav-up](https://github.com/pielco11/fav-up) 25 - This won't work be very frequently because the server must send the same response when it's accessed by the IP address, but you never know. 26 - When you collect candidate IPs, **validate them** before trusting the first hit: 27 - Send the right **Host header and SNI** (`curl --resolve`, `openssl s_client -servername ...`). 28 - Compare **status code, title, favicon hash, body hash, headers and error pages**. 29 - A direct-origin response usually **won't expose** Cloudflare-specific behavior such as `cf-ray`, `cf-cache-status`, or `/cdn-cgi/trace`. 30 - Compare the **TLS certificate SANs**, web server banner, and optional **JA3/JARM** style fingerprints to eliminate shared-hosting false positives. 31 - If the target uses **Cloudflare Tunnel** or is **originless** (for example, Workers/Pages acting as the origin), origin-IP hunting may be a dead end and you should pivot to alternate hostnames or application-layer bugs. 32 33 For more recon pivots around favicon hashes, CT logs, passive DNS and related-domain discovery: 34 35 [Readme](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/external-recon-methodology/README.md) 36 37 ## Tools to uncover Cloudflare 38 39 - Search for the domain inside [http://www.crimeflare.org:82/cfs.html](http://www.crimeflare.org:82/cfs.html) or [https://crimeflare.herokuapp.com](https://crimeflare.herokuapp.com). Or use the tool [CloudPeler](https://github.com/zidansec/CloudPeler) (which uses that API) 40 - Search for the domain in [https://leaked.site/index.php?resolver/cloudflare.0/](https://leaked.site/index.php?resolver/cloudflare.0/) 41 - [**CF-Hero**](https://github.com/musana/CF-Hero) is a comprehensive reconnaissance tool that combines current DNS, historical DNS, Shodan, Censys, ZoomEye and SecurityTrails, and can validate candidates with response matching to reduce false positives. 42 - [**CloudFlair**](https://github.com/christophetd/CloudFlair) searches Censys certificates containing the target name, extracts candidate IPv4 hosts and compares their responses. Note that, as of late 2024, free Censys accounts no longer expose the API access CloudFlair expected. 43 - [**CloakQuest3r**](https://github.com/spyboy-productions/CloakQuest3r): CloakQuest3r is a powerful Python tool meticulously crafted to uncover the true IP address of websites safeguarded by Cloudflare and other alternatives, a widely adopted web security and performance enhancement service. Its core mission is to accurately discern the actual IP address of web servers that are concealed behind Cloudflare's protective shield. 44 - [Censys](https://search.censys.io/) 45 - [Shodan](https://shodan.io/) 46 - [Bypass-firewalls-by-DNS-history](https://github.com/vincentcox/bypass-firewalls-by-DNS-history) 47 - If you have a set of potential IPs where the web page is located you could use [https://github.com/hakluke/hakoriginfinder](https://github.com/hakluke/hakoriginfinder) 48 49 ```bash 50 # Install and run CF-Hero with extra data sources enabled 51 # API keys are configured in ~/.config/cf-hero.yaml 52 53 go install -v github.com/musana/cf-hero/cmd/cf-hero@latest 54 cf-hero -f domains.txt -shodan -censys -securitytrails -title "Target title" 55 ``` 56 57 ### Fast validation of candidate origins 58 59 ```bash 60 TARGET=target.com 61 IP=1.2.3.4 62 63 # Send the real hostname in SNI + Host and inspect headers/body 64 curl -sk --resolve ${TARGET}:443:${IP} https://${TARGET}/ -D - -o /tmp/${TARGET}.body 65 66 # Compare the certificate directly exposed by the candidate IP 67 openssl s_client -connect ${IP}:443 -servername ${TARGET} </dev/null \ 68 | openssl x509 -noout -subject -issuer -ext subjectAltName 69 ``` 70 71 ```bash 72 # You can check if the tool is working with 73 prips 1.0.0.0/30 | hakoriginfinder -h one.one.one.one 74 75 # If you know the company is using AWS you could use the previous tool to search the 76 # web page inside the EC2 IPs 77 DOMAIN=something.com 78 WIDE_REGION=us 79 for ir in `curl https://ip-ranges.amazonaws.com/ip-ranges.json | jq -r '.prefixes[] | select(.service=="EC2") | select(.region|test("^us")) | .ip_prefix'`; do 80 echo "Checking $ir" 81 prips $ir | hakoriginfinder -h "$DOMAIN" 82 done 83 ``` 84 85 ## Uncovering Cloudflare from Cloud infrastructure 86 87 Note that even if this was done for AWS machines, it could be done for any other cloud provider. 88 89 For a better description of this process check: 90 91 [?Utm Campaign=Hacktrics&Utm Medium=Banner&Utm Source=Hacktricks](https%3A//trickest.com/blog/cloudflare-bypass-discover-ip-addresses-aws/%3Futm_campaign%3Dhacktrics%26utm_medium%3Dbanner%26utm_source%3Dhacktricks) 92 93 ```bash 94 # Find open ports 95 sudo masscan --max-rate 10000 -p80,443 $(curl -s https://ip-ranges.amazonaws.com/ip-ranges.json | jq -r '.prefixes[] | select(.service=="EC2") | .ip_prefix' | tr '\n' ' ') | grep "open" > all_open.txt 96 # Format results 97 cat all_open.txt | sed 's,.*port \(.*\)/tcp on \(.*\),\2:\1,' | tr -d " " > all_open_formated.txt 98 # Search actual web pages 99 httpx -silent -threads 200 -l all_open_formated.txt -random-agent -follow-redirects -json -no-color -o webs.json 100 # Format web results and remove eternal redirects 101 cat webs.json | jq -r "select((.failed==false) and (.chain_status_codes | length) < 9) | .url" | sort -u > aws_webs.json 102 103 # Search via Host header 104 httpx -json -no-color -list aws_webs.json -header Host: cloudflare.malwareworld.com -threads 250 -random-agent -follow-redirects -o web_checks.json 105 ``` 106 107 ## Bypassing Cloudflare through Cloudflare 108 109 ### Authenticated Origin Pulls 110 111 This mechanism relies on **client** [**SSL certificates**](https://socradar.io/how-to-monitor-your-ssl-certificates-expiration-easily-and-why/) **to authenticate connections** between **Cloudflare’s reverse-proxy** servers and the **origin** server, which is called **mTLS**.<sup>[[1]](#references)</sup> 112 113 Cloudflare supports **global**, **zone-level**, and **per-hostname** AOP. The important detail for attackers is that **global AOP uses a Cloudflare-provided certificate shared across all Cloudflare accounts**, so it only proves that the request came from the **Cloudflare network**, not from the victim's specific zone.<sup>[[2]](#references)</sup> 114 115 > [!CAUTION] 116 > Therefore, if the victim trusts the **global/shared AOP certificate**, an attacker can just place **their own domain in Cloudflare**, point it to the **victim origin IP**, and send traffic **from Cloudflare to the victim** while bypassing the victim's hostname-specific WAF/bot/rate-limit setup. 117 118 This is specially interesting when the target only verifies **"is this request coming from Cloudflare?"** instead of **"is this request coming from my Cloudflare configuration?"**.<sup>[[2]](#references)</sup> 119 120 ### Allowlist Cloudflare IP Addresses 121 122 This will **reject connections that do not originate from Cloudflare's** IP address ranges. However, this is vulnerable to the previous setup too: an attacker can **proxy traffic through their own Cloudflare tenant** and still reach the victim from a valid Cloudflare source IP.<sup>[[2]](#references)</sup> 123 124 If you have the origin IP, test both situations: 125 126 - Directly contacting the origin with the victim `Host` header. 127 - Reaching the origin **through your own Cloudflare zone/Worker/custom domain** and comparing which protections disappear. 128 129 ## Cloudflare-managed alternate hostnames 130 131 Sometimes you will not discover the origin IP, but you can still reach the application through **Cloudflare-owned hostnames** that the target forgot to disable: 132 133 - **Workers**: `<worker>.<account>.workers.dev` 134 - **Workers preview URLs**: `<preview>-<worker>.<account>.workers.dev` 135 - **Pages**: `<project>.pages.dev` 136 137 This does **not** reveal the origin IP, but it can bypass **hostname-specific** WAF, Access, caching, or rate-limit rules that were only tuned for the vanity domain. If you see any of these names leaked in JavaScript, source maps, CSP headers, CI logs, screenshots or public repos, hit them directly and compare the behavior with the main domain. 138 139 ## Bypass Cloudflare for scraping 140 141 ### Cache 142 143 Sometimes you just want to bypass Cloudflare to only scrape the web page. There are some options for this:<sup>[[3]](#references)</sup> 144 145 - Use Google cache: `https://webcache.googleusercontent.com/search?q=cache:https://www.petsathome.com/shop/en/pets/dog` 146 - Use other cache services such as [https://archive.org/web/](https://archive.org/web/) 147 148 ### Tools 149 150 Some tools like the following ones can bypass (or were able to bypass) Cloudflare's protection against scraping: 151 152 - [https://github.com/sarperavci/CloudflareBypassForScraping](https://github.com/sarperavci/CloudflareBypassForScraping) 153 154 ### Cloudflare Solvers 155 156 There have been a number of Cloudflare solvers developed: 157 158 - [FlareSolverr](https://github.com/FlareSolverr/FlareSolverr) 159 - [cloudscraper](https://github.com/VeNoMouS/cloudscraper) [Guide here](https://scrapeops.io/python-web-scraping-playbook/python-cloudscraper/) 160 - [cloudflare-scrape](https://github.com/Anorov/cloudflare-scrape) 161 - [CloudflareSolverRe](https://github.com/RyuzakiH/CloudflareSolverRe) 162 - [Cloudflare-IUAM-Solver](https://github.com/ninja-beans/cloudflare-iuam-solver) 163 - [cloudflare-bypass](https://github.com/devgianlu/cloudflare-bypass) \[Archived] 164 - [CloudflareSolverRe](https://github.com/RyuzakiH/CloudflareSolverRe) 165 166 ### Fortified Headless Browsers <a href="#option-4-scrape-with-fortified-headless-browsers" id="option-4-scrape-with-fortified-headless-browsers"></a> 167 168 Use a headless browser that isn't detected as an automated browser (you might need to customize it for that). Some options are: 169 170 - **Puppeteer:** The [stealth plugin](https://github.com/berstend/puppeteer-extra/tree/master/packages/puppeteer-extra-plugin-stealth) for [puppeteer](https://github.com/puppeteer/puppeteer). 171 - **Playwright:** The [stealth plugin](https://www.npmjs.com/package/playwright-stealth) is coming to Playwright soon. Follow developments [here](https://github.com/berstend/puppeteer-extra/issues/454) and [here](https://github.com/berstend/puppeteer-extra/tree/master/packages/playwright-extra). 172 - **Selenium:** [SeleniumBase](https://github.com/seleniumbase/SeleniumBase) is a modern browser automation framework featuring built-in stealth capabilities. It offers two modes: **UC Mode**, an optimized Selenium ChromeDriver patch based on [undetected-chromedriver](https://github.com/ultrafunkamsterdam/undetected-chromedriver), and **CDP Mode**, which can bypass bot detection, solve CAPTCHAs, and leverage advanced methods from the Chrome DevTools Protocol. 173 174 ### Smart Proxy With Cloudflare Built-In Bypass <a href="#option-5-scrape-with-fortified-headless-browsers" id="option-5-smart-proxy-with-cloudflare-built-in-bypass"></a> 175 176 **Smart proxies** proxies are continuously updated by specialized companies, aiming to outmaneuver Cloudflare's security measures (as thats their business). 177 178 Som of them are: 179 180 - [ScraperAPI](https://www.scraperapi.com/?fp_ref=scrapeops) 181 - [Scrapingbee](https://www.scrapingbee.com/?fpr=scrapeops) 182 - [Oxylabs](https://oxylabs.go2cloud.org/aff_c?offer_id=7&aff_id=379&url_id=32) 183 - [Smartproxy](https://prf.hn/click/camref:1100loxdG/[p_id:1100l442001]/destination:https%3A%2F%2Fsmartproxy.com%2Fscraping%2Fweb) are noted for their proprietary Cloudflare bypass mechanisms. 184 185 For those seeking an optimized solution, the [ScrapeOps Proxy Aggregator](https://scrapeops.io/proxy-aggregator/) stands out. This service integrates over 20 proxy providers into a single API, automatically selecting the best and most cost-effective proxy for your target domains, thus offering a superior option for navigating Cloudflare's defenses. 186 187 ### Reverse Engineer Cloudflare Anti-Bot Protection <a href="#option-6-reverse-engineer-cloudflare-anti-bot-protection" id="option-6-reverse-engineer-cloudflare-anti-bot-protection"></a> 188 189 Reverse engineering Cloudflare's anti-bot measures is a tactic used by smart proxy providers, suitable for extensive web scraping without the high cost of running many headless browsers. 190 191 **Advantages:** This method allows for the creation of an extremely efficient bypass that specifically targets Cloudflare's checks, ideal for large-scale operations. 192 193 **Disadvantages:** The downside is the complexity involved in understanding and deceiving Cloudflare's deliberately obscure anti-bot system, requiring ongoing effort to test different strategies and update the bypass as Cloudflare enhances its protections. 194 195 Find more info about how to do this in the [original article](https://scrapeops.io/web-scraping-playbook/how-to-bypass-cloudflare/).<sup>[[3]](#references)</sup> 196 197 ## References 198 199 - [1] [Cloudflare Docs - Protect your origin server](https://developers.cloudflare.com/fundamentals/security/protect-your-origin-server/) 200 - [2] [Using Cloudflare to bypass Cloudflare](https://certitude.consulting/blog/en/using-cloudflare-to-bypass-cloudflare/) 201 - [3] [How to Bypass Cloudflare (ScrapeOps Web Scraping Playbook)](https://scrapeops.io/web-scraping-playbook/how-to-bypass-cloudflare/)