That is the biggest Achilles heel for anyone using Cloudflare or any other reverse proxy or WAF.
If an attacker figures out your origin IP, meaning the actual IP of the server where your app is running, they can straight up bypass every single Cloudflare defense like your firewall rules, DDoS mitigation, bot protection, and blast malicious traffic directly at your machine.
Most of the time these guys aren't even hunting for you manually. They use massive databases packed with tons of leaked IPs scraped from old DNS records, email headers, or misconfigured subdomains. They just run automated tools against those lists to see what hits.
submitted by /u/siterightaway to r/StopBadBots
[link] [comments]
Source: r/StopBadBots · by /u/siterightaway