When the policeman becomes the criminal – how Cloudflare attacks my machines
kmitov.com
kmitov.com
In short, for the non-cloudflare-users among the HN crowd, and since this is a super clickbaity title, cloudflare is a reverse proxy. ALL IPs in the user's access.log, unless explicitly configured otherwise, will be cloudflare's.
Cloudflare also doesn't proactively update its cache. It does so on demand.
What I'm really confused with is if they did indeed talk to CF support, how was this not caught by the support agents? Could they genuinely be CF IPs? Having a hard time believing that.
Anyway, first step would be to look at the x-forwarded-for header. If not available, since these are logs, cloudflare has traffic analytics and wouldn't confuse its own IPs in the mix.
https://kmitov.com/posts/godaddymicrosoft-365-and-how-an-ema...
(In this case, that GoDaddy resells Office 365, and the interactions between the two.)
Here is how I would troubleshoot:
1. Look for the X-Forwarded-For header: All requests or the AWS server will come from Cloudflare. That's the point of a CDN. The X-Forwarded-For header tells you the actual client IP making the request. I think Cloudflare has some tools to block certain IP addresses. You can use that once you have identified the IP to block.
2. Make sure nginx returns appropriate headers so that Cloudflare will cache the responses from the origin server. If caching is set up correctly, Cloudflare will not make requests to your server. They will serve from their cache instead.
Every day (to this day) we're getting thousands of requests for images that no longer exist on our CDN (because they were stale/deleted). The CDN normally does not hit the origin machine (where the images are hosted) unless it cannot find the images on the CDN, at which point it queries the origin for the image. Problem was, the image no longer existed on the origin. I didn't expect the origin would receive much traffic, but suddenly it's receiving a ton of traffic.
I was very confused because, at first glance, it looked like I was being attacked by my own CDN provider given the tremendous traffic and the fact that the CDN provider was the only thing allowed to access that box (the origin).
At any rate, I contacted the CDN provider and informed them that thousands of requests that resulted in 404's were taking down my website. They told me there was nothing they could do.
In any case, I managed to wrangle together some new infra to handle it. I don't think whoever was hitting the CDN for those images was malicious. However, it occurred to me that had they been malicious, then they could have just hit random non-existent file-names at a much higher rate and done a lot more damage.
However, given how long it took to get an answer to a very simple, basic question about reported abuse, I don't know if you'll get a satisfactory answer about why this is happening.
Please do report back if you do find out more.
Human on a phone for technical issues starts at $500/month + 3% net spend though.
Author may also want to review cache headers returned for their content as it should be possible to cache at CDN effectively indefinitely.
The article is a little light on data though. No vertical axis, no information on the volume of data transferred or the associated costs. I feel like its pertinent information, and if the numbers are small enough that it makes the title seem silly well.. dial it down a little, I guess.
Spending more money on increasing infrastructure rather than reading through Cloudflare’s documentation and offerings seems kind of a waste…
This surprises me. I thought the only thing DO said no to - is anything at all that might protect us from malicious, DO hosted traffic.
I kinda wonder if someone's using https://workers.cloudflare.com/ to crawl their site daily. Or they just need to configure `ngx_http_realip_module` to get the originating user's IP address, if they're not currently processing the X-Forwarded-For header.
These are extraordinary claims, which require extraordinary evidence.
And from Cloudflare IPs.
The same happens with most load balancers. In Apache, you have to set up mod_rpaf or mod_remoteip. In Nginx, you have to configure ngx_http_realip_module.
How much can those cost him? Not more than a few pennies per month, right?
He could just stop using CloudFlare if he does not like it.
Calling it an "attack" is a bit much.