How hackers bypass cloudflare & other reverse proxy solutions

Поделиться
HTML-код
  • Опубликовано: 11 сен 2024
  • In this video, I go through how can you bypass reverse proxies put in place.
    Books to get started on hacking:
    1. Hacker's Handbook - amzn.to/4aH5msF
    2. Real World Bug Hunting - amzn.to/48Msi7N
    3. Certified Blackhat - amzn.to/3tG7QXB
    4. Linux For Hackers - amzn.to/47plE6E
    5. Black Hat Python - amzn.to/48N3k8D
    PC I use: amzn.to/3S6XERh
    NOTE: This video is purely for educational purposes.
    Tags:
    #reverse #proxy #ethicalhacking #ctf #bug #bounty #hacker #hacking #cloudflare #akamai #bypass

Комментарии • 24

  • @grandmat2561
    @grandmat2561 Год назад +10

    If cloudflare is correctly setup, you can't access the ip adress directly. This works in extremely précise cases.

    • @ItsVaness_official
      @ItsVaness_official Год назад

      There are still ways to bypass that, for example I know about XenForo bypass that will give you real IP. Most of XenForo websites don't know about that, but it's simple.

    • @Klinoklaz
      @Klinoklaz 2 месяца назад

      i can still see my server's real ip in email headers. is there a way to set up cloudflare to proxy emails?

    • @shazzz_land
      @shazzz_land 2 месяца назад

      If you do a whois don t u get the home ip?

  • @OMNICOMPETENTEST
    @OMNICOMPETENTEST 5 месяцев назад +4

    Your mic sounds really good (after the video ends)

  • @christian84726
    @christian84726 7 месяцев назад +2

    It did not work like this. Cloudflare proxy is in the datacenter of the customer it make a tunnel direktly to the internal ip the webservice did not have a direkt ip in public

    • @RahulSinghInfosec
      @RahulSinghInfosec  7 месяцев назад +1

      The video talks about a misconfiguration. If you still have some doubts, I would suggest looking up some reports on H1 and even referring some cloudflare documentation around origin IP misconfiguration. That will help :)

    • @christian84726
      @christian84726 7 месяцев назад

      @@RahulSinghInfosec thx I will Look at it

    • @christian84726
      @christian84726 7 месяцев назад +1

      @@RahulSinghInfosec would u mind if u explain it in more Detail what u means also with h1

  • @Roshan12pc
    @Roshan12pc 10 месяцев назад +2

    How can we use it in web scraping

  • @samuelkojoquansah8115
    @samuelkojoquansah8115 6 месяцев назад

    Amazing information

  • @Exodus-ze1pr
    @Exodus-ze1pr 11 месяцев назад +2

    if i got the orgin ip and the webpage loads ,so can i report it as a vulnerablity?

    • @RahulSinghInfosec
      @RahulSinghInfosec  11 месяцев назад +4

      Yes def. I think it might be eligible for a bounty as well. I have seen a report on h1 which showed origin ip and waf bypass

    • @Exodus-ze1pr
      @Exodus-ze1pr 11 месяцев назад +8

      @@RahulSinghInfosec Bro i reported it and got 100$ bounty

    • @shazzz_land
      @shazzz_land 2 месяца назад

      ​@@Exodus-ze1prseriously? for just finding out the real ip of the server?

    • @shazzz_land
      @shazzz_land 2 месяца назад

      ​@@RahulSinghInfosecwhat other entry level bounty hunting things are there besides revealing true ip?

    • @shazzz_land
      @shazzz_land 2 месяца назад

      ​@@Exodus-ze1pra digital bounty should be of a minimum of 1k

  • @AliAhmed-gu6wy
    @AliAhmed-gu6wy 7 месяцев назад

    Can I talk to you

  • @soufianeloua
    @soufianeloua Год назад +3

    how to contact u ?

  • @miask8965
    @miask8965 4 месяца назад

    despite being indian i liked your vídeo