2 ms·
We're talking about a situation where an attacker would create the service disruption by enabling Host header checks on an origin server that the attacker doesn
by EB66 6y ago
We're talking about a situation where an attacker would create the service disruption by enabling Host header checks on an origin server that the attacker doesn't own. So a warning wouldn't help because that warning would be displayed to the attacker.
The logic is tricky, but in the end origin server ownership verification is what's required to safely support Host header checks.
- floatingatoll 6y agoIf the attacker is logged into the Cloudflare control panel, where presumably the warning would be displayed — where else could it be displayed? certainly not on the content served to end users — then, yes, the attacker could clear the warning. They could also change the origin servers, or do countless other things to disrupt service, that do not require modifying an origin server. I consider that an acceptable failure case for the warning. I'm not arguing for or against ownership verification, but there is opportunity to improve here that does not depend on the question of ownership verification.