Threat Actors Abuse Cloudflare Tunnel for Persistent Access, Data Theft
securityweek.com
securityweek.com
It is amazing to me that if AT&T came out and said they were buying up every other ISP in the world to form one big unified network HN would be losing their shit, but Cloudflare slowly boils the frog and everyone cheers and evangelizes for them.
Avoid these predators.
In my opinion battle is kinda over because 99.9% of people want ready to use product not contributing anything (consumers vs prosumers).
What the remaining 0.1% can do? Build your own overlay VPN networks and put services there. Treat Internet just like transport layer. Make mirrors of interesting stuff and put in there. It might grow...
Government must issue driving licenses and restrict who gets to drive vehicles.
Nobody is suggesting shutting down Cloudflare or its services. It's just pointing out an attack technique that is being used.
This thread is absurd!
Is there such law where you are?
B. Bank robbers likely have driver's licenses.
1) There is a protocol for communication that encodes some useful heuristic for regular operations - IP addresses, for example, or ports. 2) Idiots decide that ONLY EVER COMPLETELY SAFE traffic should be allowed. As a result, all communications are gone. 3) That's not workable, so some channels have to be opened. 4) Someone develops a way to encode all the previous uses, including the necessary administrative ones, AND necessarily the malicious ones, over this protocol. 1) as 1) but with an extra layer that now does nothing.
A very* similar process exists for scripting languages. "Why are our employees so unproductive, manually doing easily automated things that security won't let them automate? -> Hey, wouldn't it be great if we could automate all the things with [X]? -> Oh noes, malware!".
If a device on your network suddenly runs "a script that just loads some remote HTTP address for evil things to do next" that connection attempt to some strange remote HTTP address is a great indicator that you've got a compromised system somewhere. When all traffic, good and evil, flows to/from cloudflare it's harder to spot the evil.
On a more general note, tangential to the article and specifically regarding blocking DoH and friends, it's pretty trivial to do this with a DNS backed firewall. I do this for my IoT vlan:
- default deny all outbound
- set dnsmasq to populate an ipset/nftset with DNS responses
- have a firewall rule that hole punches for traffic destined for any ip in the set
- now it's just DNS filtering like usual
This means any successful outbound connection must be prefixed with a successful DNS query that is resolved by the local Dnsmasq instance. Any query that hits an unblocked DNS endpoint does not populate the set used for whitelisting, and is dead in the water - making DoH, DoT, DoQUIC, and such unviable.
Obviously, hole punch exceptions as needed (E.g. For direct connects to static ip addresses).
It may work in the limited context that is your IoT network but for any corp, user of the web, etc Cloudflare IPs will open almost immediately for all but the most selective (non-CF) DNS records.
Or you don’t allow any CF DNS records or IP ranges and cut yourself off from half the internet.
That’s what parent meant.
See: https://developers.cloudflare.com/cloudflare-one/connections...