• Tm12@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 hours ago

    Cloudflare is more than just DNS. They provide CDN, bot blocking and storage. They most certainly can fuck you up.

    • mic_check_one_two@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      5
      ·
      5 hours ago

      Is Anubis a DNS service? I was under the impression that it was basically just a reverse proxy that you ran, which required a proof-of-work before it would pass the request off to your various services. If that’s the case, it’s doing a fundamentally different job than CloudFlare is. Because the DNS will likely hit CloudFlare before being forwarded to your Anubis. Like the order of the request would be:
      User>CloudFlare DNS>Anubis>Site
      If that’s the case, using Anubis wouldn’t change the fact that it’s being blocked by CloudFlare.

      If Anubis is an actual DNS service, I may need to look into it more for my own use. I hadn’t bothered, because I thought it was more like Nginx.

      • Tm12@lemmy.ca
        link
        fedilink
        English
        arrow-up
        4
        ·
        4 hours ago

        Anubis is self-hosted AI firewall defence. Parent comment is weird.

  • Coopr8@kbin.earth
    link
    fedilink
    arrow-up
    13
    ·
    1 day ago

    I don’t understand how CloudFlare is intermediating the traffick in this case. How can CloudFlare block the sites if they aren’t hosted on CloudFlare or using CloudFlare services? Are they acting as an ISP in the UK?

      • Coopr8@kbin.earth
        link
        fedilink
        arrow-up
        5
        ·
        1 day ago

        So the ISP redirects the request from the primary host to the CloudFlare cache under some conditions? but wouldn’t that be ineffective at blocking the sites of the browser still attempts to pull from the primary host first? I’m assuming this must be mediated by the ISP somehow otherwise it would just be a browser setting to only pull from the primary host of the domain.

        • cyrano@lemmy.dbzer0.comOP
          link
          fedilink
          English
          arrow-up
          4
          ·
          1 day ago

          Cloudflare operates as a reverse proxy between a user’s browser and the origin server of a website or application. When a user requests a webpage, the request is first routed through Cloudflare’s global network instead of directly to the origin server. Cloudflare then forwards the request to the origin server, retrieves the content, and sends it back to the user.

          It is doing that by being authoritative DNS provider and providing useful features in case of attack but imagine that everyone start using cloudflare then it become the authority DNS wise.

      • guybrush_threepwood_MP@lemmy.dbzer0.com
        cake
        link
        fedilink
        English
        arrow-up
        2
        ·
        16 hours ago

        I bumped into at least one site blocked by cloudflare. When accessing the site, I’m redirected to:

        https://www.cloudflare-terms-of-service-abuse.com/stream.ts

        So far it happens when I try the landing page of the site, if I go pages I visited in the past I can reach the intended site. Maybe the name resolution is cached.

        I haven’t tested it much but I’m using Quad9 and it’s not making any difference.

        Cloudflare seems to be the SOA for the affected sites and then it sets *.ns.cloudflare.com as the primary source and dns.cloudflare.com as the administrator.

        To my understanding Quad9, being a recursive DNS resolver, is not the main DNS authority in this case. Quad9 will reach out to cloudflare to refresh the records when the TTL expires and then cloudflare can return a different IP for the domain.

        Either affected sites stop using cloudflare, or we reach them via TOR, if they have that option.

        • MrSoup@lemmy.zip
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          6 hours ago

          It happened to me once with 1337x redirecting to that stream.ts, i deleted the prepending “www.” and it worked again.

    • AnarchistArtificer@slrpnk.net
      link
      fedilink
      English
      arrow-up
      10
      ·
      1 day ago

      The constant stream of piracy related utilities that end in “rr” never ceases to amuse me.

      Bonus joke! “What’s a pirate’s favourite letter of the alphabet?”

      (People often say Arrrrr! here, especially if you seed that context earlier in the conversation)

      “You’d think so, but actually it’s C”