6 ms·
If you come back tomorrow, I can probably turn CloudFlare off. Although I understand not being enthusiastic enough about my novelty website to bother.
by serentty 4y ago
If you come back tomorrow, I can probably turn CloudFlare off. Although I understand not being enthusiastic enough about my novelty website to bother.
- rkagerer 4y agoAre there any tricks a user can do to bypass Cloudflare or force a cache invalidation?
- arjvik 4y agoThat would entirely defeat the purpose of cloudflare's DDoS protections.
- serentty 4y agoYeah, I imagine it would. I can invalidate the cache myself, but it would not make sense for a user to do so.
- serentty 4y agoIf you want to visit the page directly without CloudFlare, go to http://trombone.zapto.org http://trombone.zapto.org instead.
- rkagerer 4y agoNice! Thanks for serving me. It was snappier than expected.
- jesprenj 4y agoSomehow getting the IP address of the server (in this case 174...*) would enable you to connect directly. Websites, such as crimeflare.org crawled the net to gather those addresses, probably by scanning, but the mentioned site was shut down as it seems.
- hunter2_ 4y agoA site that really wants Cloudflare's protection would ignore all traffic that doesn't come from Cloudflare though. In practice, many origins probably aren't locked down in this fashion.
- zhfliz 4y agogenerally, adding random query params like ?1, ?2, ?12345 helps with the default settings of including that in the cache key. that will also work in this instance. you won't however see it slowly send the response as you do on http://trombone.zapto.org/ http://trombone.zapto.org/, as cloudflare seems to block until it received the full response from the backend.
- freedomben 4y agoYou're not wrong, but all of that behavior is configurable so may work on some sites and not others. The account owner can tell cloudflare whether to consider query params different or the same for cache hit puproses. You can also configure whether cloudflare streams/buffers (although some of it does require the enterprise plan). No affiliation with cloudflare other than I use them for several sites.
- zhfliz 4y agoindeed, hence > helps with the default settings of including that in the cache key I didn't know about response streaming being configurable, it seems to be enabled by default and configurable for enterprise customers: https://support.cloudflare.com/hc/en-us/articles/206049798-Setting-up-Response-Buffering https://support.cloudflare.com/hc/en-us/articles/206049798-S... I assume due to the (relatively) small response size of this page it buffers regardless.
- nonrandomstring 4y agoPlease for the love of kittens turn off Cloudflare and never put it on again. For me and other Tor users that awful service is a guaranteed way of ensuring we'll never see your site (which I am very interested in BTW).
- serentty 4y agoYeah, sorry about that. I am planning on finding a way to keep things interesting and authentic with the hosting, but also accessible to everyone. In the meantime, if you want to visit the page directly without CloudFlare, go to http://trombone.zapto.org http://trombone.zapto.org instead.
- nonrandomstring 4y agoI use a text based browser from my editor and that loads as close to instantly as you'd ever hope for! A VIC-20 version sounds even more awesome.
- hsbauauvhabzb 4y agoIf you care about privacy, using a text based browser from an editor is a terrible idea for many reasons, lol.
- nonrandomstring 4y agoSounds interesting. Do share. What's your threat model?
- hsbauauvhabzb 4y agoAssuming emacs, attacking major mode detection, or triggering lisp execution. Edit: but also identifying heuristics like lack of JS execution, or potentially client specific http client behaviour
- hsbauauvhabzb 4y ago