5 ms·
> injected a JS analytics snippet in my HTML-only JS-free site textlog.cc Cloudflare injected hostile code into a site they are not even hosting? If it's HTTP
by Animats 2mo ago
> injected a JS analytics snippet in my HTML-only JS-free site textlog.cc
Cloudflare injected hostile code into a site they are not even hosting?
If it's HTTPS, how do they even do that?
Does it violate the "exceeds authorized access" provision in the Computer Fraud and Abuse Act?
- deleted 2mo ago[deleted]
- bawolff 2mo agoThe most likely answer is the person accidentally enabled the cloudflare reverse proxy without understanding what they were doing. It seems incredibly unlikely cloudflare does this when just DNS hosting, if for no other reason then that this would break so many things.
- stagas 2mo agoI can’t recall if there was a setting to enable reverse proxy, if there was it was On by default since I didn’t expect to have reverse proxy enabled as well. But you can also rp without injecting a script. That’s overdoing it.
- eaf7e281 2mo agoIf the cloud symbol is orange, it's enabled. I believe they'll even warn you if you disable it, a lot of people enable it unintentionally.
- dboreham 2mo agoI don't know what happened in this situation but beware that CF and similar providers are not true DNS hosting providers. They do DNS, but only so their CDN stuff works, and to lock their customers from using whatever DNS hosting they want. Various things that one might reasonably want to do with your DNS zone are not possible with their product. So use it only because you need to do so in conjunction with their core services.
- kazinator 2mo agoIf this is HTTPS, how would Cloudfare have the certificate for your domain so that browsers don't warn about a mismatch? Or is it that when you sign over DNS to a provider, they can take over your cert? They can "ass-cert" their own? :)
- threecheese 2mo agoAs far as I know they terminate all TLS; it’s one of the tradeoffs using them.
- muvlon 2mo agoThey have a product called Magic Transit that offers DDoS protection and such for plain IP traffic, where Cloudflare does not terminate TLS. Pricing is not public but starts in the five-digit USD per month range according to people I talk to. This may tell you something about how keen Cloudflare are to handle traffic they themselves cannot decrypt.
- bawolff 2mo agoMagic Transit uses BGP magic to work. That only makes sense at scale - i believe you have to have your own ASN for it to work. Realistically its a totally different product, and 5 digit price is probably cheap relative to competitors in that space.
- muvlon 2mo agoNope, you don't need your own AS for this to work, nor do you need to use BGP. They support static routes too. BGP peering support is actually "beta" according to Cloudflare: https://developers.cloudflare.com/magic-transit/get-started/#ips https://developers.cloudflare.com/magic-transit/get-started/... You do ideally want your own /24, though even that's not a hard requirement. And it can be provider-assigned space as long as your provider is willing to sign an LOA for you. As for competitors, there are a few that start in the low 4 digits per month for similar services. That's not to say Cloudflare doesn't have anything unique to offer though, they're great at scale and standardization.
- MrJohz 2mo agoWhen you set up CNAME and certain other records in Cloudflare DNS, it defaults to (and heavily discourages you to disable) "proxied" records, which I believe means that the record points to a Cloudflare-owned host which then acts as a reverse proxy to whatever value you'd set. So from the console it looks like you've set the CNAME to a certain value, but in practice it'll be set to a different thing and transparently forward everything via Cloudflare. This is probably where the analytics get inserted, alongside a bunch of other Cloudflare features. You can disable this, at which point the record will be set as a normal DNS record. I can see the advantage of Cloudflare's proxy systems, but I wish they'd be clearer about when they're being used and not pretend that this is some DNS feature or that records have been set to one thing when they've actually been set to something else. If nothing else, it makes debugging DNS issues a lot more confusing, particularly if you're not a DNS expert.
- gruez 2mo ago>I can see the advantage of Cloudflare's proxy systems, but I wish they'd be clearer about when they're being used and not pretend that this is some DNS feature or that records have been set to one thing when they've actually been set to something else. If nothing else, it makes debugging DNS issues a lot more confusing, particularly if you're not a DNS expert. You could say the same about the reverse, ie. people set up their site on cloudflare, thought it was "protected", but really it's dns only and their servers are wide open. It's even worse if they migrated from another provider that was providing ddos protection.
- MrJohz 2mo agoI don't think this particular feature helps there, though. If you set your site up on Cloudflare, you'll probably explicitly want the proxy stuff, and that's very easy to set up. But if you buy a domain on Cloudflare, then you're already not looking specifically at the proxy products, you're looking at something else. And if you start configuring that domain in an admin panel that looks like it's offering you direct DNS configuration, and then you later realise that the DNS configuration has ended up completely different to how you set it up, then that's a bit weird. Like, if I set `CNAME` in DNS, then I expect the DNS CNAME record to be what I set it to.
- Aeolun 2mo ago> It seems incredibly unlikely cloudflare does this when just DNS hosting Not to mention impossible when ‘just’ DNS hosting. Though I suppose they could secretly replace the stated IP with one of their own anyway and then still proxy the content.
- Touchnow 2mo agoTLS terminates at Cloudflare, not at your origin. When a record is proxied (the orange cloud), CF holds the certificate the browser validates against and opens a separate connection to your server, so it sees plaintext on both sides and can rewrite the HTML on the way out. Same mechanism that makes the WAF and caching work, so it isn't specific to the analytics feature. Worth checking which of your records are actually proxied. DNS-only ones (grey cloud) pass straight through and can't be touched.