u0m3 Posted January 19, 2018 Report Posted January 19, 2018 Synopsis: In the past few weeks, I found that multiple websites using Cloudflare were misconfigured, and allowed an attacker to bypass any Cloudflare protection in place easily. Several of the companies behind these websites had more than 1 million users and were among the top companies of their market segment. Link: https://blog.christophetd.fr/bypassing-cloudflare-using-internet-wide-scan-data/ GitHub: https://github.com/christophetd/CloudFlair Quote