# zidansec/CloudPeler

CrimeFlare is a useful tool for bypassing websites protected by CloudFlare WAF, with this tool you can easily see the real IP of websites that have been protected by CloudFlare. The resulting information is certainly very useful for conducting further penetration testing, and analyzing websites with the same server.

Repository: https://github.com/zidansec/CloudPeler
Canonical: https://ross.abutalabs.com/products/cloudpeler
Homepage: https://zidansec.com
Language: PHP
License: MIT
License Family: permissive
Topics: bypass-cloudflare, bypass-waf, cloudflare, crimeflare, exploit, hack-tool, information-gathering, osint-tool, penetration-testing, pentest-tool, security-tools, bypass-hostname, crimeflare-next-generation, crimepeler, dns-security
Archived: true
Last push: 2023-09-01T04:16:45+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 1574, "days_push": 1097, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1576, forks 192 (observed 2026-08-28T04:05:05.991714+00:00)

## What it is
CrimeFlare is a PHP command-line OSINT tool that attempts to reveal the real origin IP address behind websites protected by Cloudflare's WAF. It gathers DNS records, nameservers, hostname, organization, and geolocation data useful for further penetration testing reconnaissance.

## Use cases
- find the real IP behind a Cloudflare-protected website
- gather DNS and nameserver info for a target domain during recon
- locate the hosting organization and geolocation of a hidden origin server
- enumerate websites sharing the same origin server
- prepare reconnaissance data before a penetration test
- check whether a domain's Cloudflare protection can be bypassed

## When to choose
- you need a quick, simple CLI tool to attempt Cloudflare origin IP discovery
- you are doing authorized penetration testing or OSINT research on a target
- you want DNS, WHOIS-style, and geolocation details in one run

## When to avoid
- you need a guaranteed bypass - the tool explicitly does not guarantee 100% success
- you are not authorized to test the target website
- you need a maintained, actively updated tool - the project has had periods of being non-functional
- you need a GUI or a non-PHP environment

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: security, osint, networking, cli
- domain: security, penetration-testing, osint, networking
- platform: cli, php
- tags: cloudflare-bypass, waf-bypass, dns-lookup, real-ip-discovery, pentest-recon, php-tool, information-gathering, linux

## Member repositories
- zidansec/CloudPeler (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:05.991714+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:57:26.253359+00:00, confidence not recorded.
  - readme: https://github.com/zidansec/CloudPeler (fetched 2026-08-28T04:05:05.991714+00:00, sha 7dec272b485e)
  - homepage: https://zidansec.com (fetched 2026-08-29T11:27:30.070401+00:00, sha f62c5a31b8b4)
- Data as of 2026-08-30T08:39:29.467469+00:00.
