
🔎 Encuentra servidores de origen de sitios web detrás de CloudFlare utilizando datos de escaneo a nivel de Internet de Censys.
Nota importante: A partir de finales de 2024, Censys ya no proporciona acceso a la API para cuentas gratuitas. Esto significa que CloudFlair ya no funciona con cuentas gratuitas de Censys.
CloudFlair es una herramienta para encontrar servidores de origen de sitios web protegidos por CloudFlare (o CloudFront) que están expuestos públicamente y no restringen adecuadamente el acceso de red a los rangos de IP del CDN correspondiente.
La herramienta utiliza datos de escaneo de Internet global de Censys para encontrar hosts IPv4 expuestos que presentan un certificado SSL asociado con el nombre de dominio del objetivo. Se requieren claves de API, que se pueden obtener desde tu cuenta de Censys.
Para más detalles sobre esta mala configuración común y cómo funciona CloudFlair, consulta la publicación del blog complementaria en https://blog.christophetd.fr/bypassing-cloudflare-using-internet-wide-scan-data/.
Así se ve CloudFlair en acción.
$ python cloudflair.py myvulnerable.site
[*] The target appears to be behind CloudFlare.
[*] Looking for certificates matching "myvulnerable.site" using Censys
[*] 75 certificates matching "myvulnerable.site" found.
[*] Looking for IPv4 hosts presenting these certificates...
[*] 10 IPv4 hosts presenting a certificate issued to "myvulnerable.site" were found.
- 51.194.77.1
- 223.172.21.75
- 18.136.111.24
- 127.200.220.231
- 177.67.208.72
- 137.67.239.174
- 182.102.141.194
- 8.154.231.164
- 37.184.84.44
- 78.25.205.83
[*] Retrieving target homepage at https://myvulnerable.site
[*] Testing candidate origin servers
- 51.194.77.1
- 223.172.21.75
- 18.136.111.24
responded with an unexpected HTTP status code 404
- 127.200.220.231
timed out after 3 seconds
- 177.67.208.72
- 137.67.239.174
- 182.102.141.194
- 8.154.231.164
- 37.184.84.44
- 78.25.205.83
[*] Found 2 likely origin servers of myvulnerable.site!
- 177.67.208.72 (HTML content identical to myvulnerable.site)
- 182.102.141.194 (HTML content identical to myvulnerable.site)
(Las direcciones IP de este ejemplo han sido ofuscadas y reemplazadas por IPs generadas aleatoriamente)
$ export CENSYS_API_ID=...
$ export CENSYS_API_SECRET=...
$ git clone https://github.com/christophetd/CloudFlair.git
cd CloudFlair
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
python cloudflair.py myvulnerable.site
o para CloudFront
python cloudflair.py myvulnerable.site --cloudfront
$ python cloudflair.py --help
usage: cloudflair.py [-h] [-o OUTPUT_FILE] [--censys-api-id CENSYS_API_ID] [--censys-api-secret CENSYS_API_SECRET] [--cloudfront] domain
positional arguments:
domain The domain to scan
options:
-h, --help show this help message and exit
-o OUTPUT_FILE, --output OUTPUT_FILE
A file to output likely origin servers to (default: None)
--censys-api-id CENSYS_API_ID
Censys API ID. Can also be defined using the CENSYS_API_ID environment variable (default: None)
--censys-api-secret CENSYS_API_SECRET
Censys API secret. Can also be defined using the CENSYS_API_SECRET environment variable (default: None)
--cloudfront Check Cloudfront instead of CloudFlare. (default: False)
Se proporciona una imagen Docker ligera de CloudFlair (christophetd/cloudflair). Se puede instanciar fácilmente un escaneo usando el siguiente comando.
$ docker run --rm -e CENSYS_API_ID=your-id -e CENSYS_API_SECRET=your-secret christophetd/cloudflair myvulnerable.site
También puedes crear un archivo con la definición de las variables de entorno y usar la opción --env-file de Docker.
$ cat censys.env
CENSYS_API_ID=your-id
CENSYS_API_SECRET=your-secret
$ docker run --rm --env-file=censys.env christophetd/cloudflair myvulnerable.site
Probado en Python 3.6. Si tienes informes de errores o preguntas, no dudes en abrir un issue.