"Uncovering Bad Guys Hiding Behind CloudFlare" 08-08-2013, 12:57 PM
#1
As I've always said, Cloudflare is relatively useless against attacks. It's even more apparent from looking at the site below, which publishes the IP addresses of Cloudflare sites. This opens the sites up to DDOS attacks if they don't have further protection. Their lists may prove useful to you guys.
Link: http://www.cloudflare-watch.org/cfs.html
Quote:Uncovering bad guys hiding behind CloudFlare
A number of sites on the web specialize in collecting data from nameservers. Some are serious research sites, while the rest are sites claiming that various domain names are worth big bucks in potential ad revenue, based on their traffic.
We found several lists of domains that use CloudFlare's nameservers by consulting search engines. CloudFlare maintains over 100 nameservers. Each customer's domain is assigned two of them with duplicate information, and CloudFlare claims nearly a half-million domains in their system. This means one million divided by one hundred, or nearly ten thousand domains per name server. (CloudFlare uses "anycast," which means that each nameserver can also show records from any of the other nameservers.) Even a quality website that specializes in nameserver data will list only a sampling of domains that use each nameserver. There is no way we know of to get a complete list of domains from a nameserver through public web access — not when there are thousands of domains on that server. To query a nameserver for public records, you must specify the domain that is the object of your query.
Once assigned, a new CloudFlare customer lists the two nameservers in their whois registration as the authoritative nameservers for their domain. You can easily check if a particular domain is on CloudFlare's nameservers, even while you cannot discover all the domains hosted on any specific large nameserver. Customers can access a control panel through CloudFlare to change nameserver records for their domain. There are also automatic changes that may be quietly imposed by CloudFlare under certain conditions.
Since customers can fiddle with their nameserver records, there is a fair amount of churn happening behind any list of domains that use CloudFlare. If connectivity seems intermittent, for example, a customer might set his control panel to bypass CloudFlare temporarily. CloudFlare does not handle email, and some customers need a special MX record for email. Subdomains are another source of confusion, as these records must be listed a certain way to keep them hidden. If the customer isn't careful, a public "direct-connect" IP address might be triggered for that customer's domain, and it might persist until the customer takes steps to keep it hidden.
Link: http://www.cloudflare-watch.org/cfs.html










![[Image: 7ajmN5P.jpg]](https://i.imgur.com/7ajmN5P.jpg)
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)