christophetd/CloudFlair
🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys. observed · 2026-08-28
Health v2 · maintenance only
41/100
- Activity 19
- Release rhythm 35
- Longevity 100
Flags: no_releases no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3155
- days_rel: n/a
- days_push: 489
- n_releases_24m: 0
Adoption not part of the score
2972 stars · 383 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
CloudFlair is a Python CLI tool that finds the origin servers of websites protected by Cloudflare or CloudFront by searching Censys internet-wide scan data for exposed hosts presenting SSL certificates matching the target domain. It automates detection of a common CDN misconfiguration where origin servers don't restrict access to CDN IP ranges.
Use cases
- find origin server behind cloudflare
- bypass cloudflare protection for a website
- identify misconfigured CDN origin servers
- pentest recon on cloudflare-protected sites
- check if my origin server is exposed
- find real IP of a website using censys
When to choose
- you're doing authorized penetration testing or bug bounty recon on a Cloudflare-protected site
- you want to audit whether your own origin servers are publicly reachable
- you have a paid Censys API account and want automated origin discovery
When to avoid
- you only have a free Censys account, since API access is no longer available for free tiers
- you need a general-purpose vulnerability scanner rather than a single-purpose origin discovery tool
- you're looking for a Cloudflare bypass that works without internet-wide scan data
Facets
cli-tool · maturity maintenance
osint penetration-testing security networking security penetration-testing osint networking python cli windows cloudflare-bypass origin-server-discovery censys cdn-misconfiguration recon linux macos
4 sources
- readme: https://github.com/christophetd/CloudFlair · fetched 2026-08-28 · ba77ac230205
- homepage: https://blog.christophetd.fr/bypassing-cloudflare-using-internet-wide-scan-data/ · fetched 2026-08-29 · a78a81e8e8f2
- site_page: https://blog.christophetd.fr/stop-worrying-about-allowprivilegeescalation · fetched 2026-08-29 · 306e080b0c79
- site_page: https://christophetd.fr · fetched 2026-08-29 · 64b0ee285788
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| christophetd/CloudFlair | main | 41 |
For agents
markdown · JSON · MCP: product_card(name="christophetd/CloudFlair")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem