3 ms·
But in order to safely enable that check for all requests that go from CloudFlare to the origin IP, you would first need to verify ownership of the origin IP.
by EB66 6y ago
But in order to safely enable that check for all requests that go from CloudFlare to the origin IP, you would first need to verify ownership of the origin IP.
You wouldn't want users who don't own the origin IP to be able to turn on that sort of check and potentially cause a service disruption. It could be the case that the legitimate owner already has a Host header mismatch in their HTTP requests/responses.
- floatingatoll 6y agoPresenting a warning about possible misconfiguration to the customer need not create a service disruption.
- EB66 6y agoWe're talking about a situation where an attacker would create the service disruption by enabling Host header checks on an origin server that the attacker doesn't own. So a warning wouldn't help because that warning would be displayed to the attacker. The logic is tricky, but in the end origin server ownership verification is what's required to safely support Host header checks.
- floatingatoll 6y agoIf the attacker is logged into the Cloudflare control panel, where presumably the warning would be displayed — where else could it be displayed? certainly not on the content served to end users — then, yes, the attacker could clear the warning. They could also change the origin servers, or do countless other things to disrupt service, that do not require modifying an origin server. I consider that an acceptable failure case for the warning. I'm not arguing for or against ownership verification, but there is opportunity to improve here that does not depend on the question of ownership verification.