CloudFlare Main Site Security Wholes 03-03-2012, 06:07 PM
#1
First I Will Tell You Its Vulnerabilities
1.Apache mod_negotiation filename bruteforcing
mod_negotiation is an Apache module responsible for selecting the document that best matches the clients capabilities, from one of several available documents. If the client provides an invalid Accept header, the server will respond with a 406 Not Acceptable error containing a pseudo directory listing. This behaviour can help an attacker to learn more about his target, for example, generate a list of base names, generate a list of interesting extensions, look for backup files and so on.
This vulnerability affects Web Server.
This vulnerability affects Web Server.
How To Attack
Pattern found:
Pattern found:
Code:
<title>406 Not Acceptable</title>2.Login page password-guessing attack
Vulnerability description
A common threat web developers face is a password-guessing attack known as a brute force attack. A brute-force attack is an attempt to discover a password by systematically trying every possible combination of letters, numbers, and symbols until you discover the one correct combination that works.
This login page doesn't have any protection against password-guessing attacks (brute force attacks). It's recommended to implement some type of account lockout after a defined number of incorrect password attempts. Consult Web references for more information about fixing this problem.
This vulnerability affects /login.
Use This Method To Attack
Vulnerability description
A common threat web developers face is a password-guessing attack known as a brute force attack. A brute-force attack is an attempt to discover a password by systematically trying every possible combination of letters, numbers, and symbols until you discover the one correct combination that works.
This login page doesn't have any protection against password-guessing attacks (brute force attacks). It's recommended to implement some type of account lockout after a defined number of incorrect password attempts. Consult Web references for more information about fixing this problem.
This vulnerability affects /login.
Use This Method To Attack
Code:
act=login&login_email=fqZVLEDF%40www.cloudflare.com&login_pass=ez3WAWbp&send_to=1Other Hidden Vulnerability:
Code:
https://www.cloudflare.com/api_json.html?a=stats&tkn=799df833d7a42adf3b8e2fd113c7260b955b8e95ac42c&u=%3F%3F%40%3F%3F.in&z=%3F%3F.inThis Tutorial Produced By Marks-Man
Enjoy


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)