Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
CF-Shield – An open source tool to protect any website with Cloudflare (github.com/sakura-sx)
17 points by Sakura-sx 8 months ago | hide | past | favorite | 15 comments


How does it differ from existing Cloudflare DDoS protection on free tier? https://www.cloudflare.com/en-gb/ddos/


It captchas everyone when there is an attack.


You mean "to further the browser monopoly".


Sir, I work against Cloudflare's monopoly on Voxga Research. But for a lot of people it is practical.


It was fun making it, I hope you like it :3


If bloating the web and centralizing it is your goal, you did well. Clownflare would die if it weren't for the oblivious customers such as yours


Hey, you go and stop every DDOSing asshole out there and I'll be glad to express that cloudflare should go away. Otherwise, those paying per-byte on bandwidth overage are more than glad to have a safety layer.


If your goal is to decentralize the web, you can buy our offerings at Voxga Research (voxga.es). We are a direct competitior to Cloudflare on the DDoS protection space.


That looks cool. So, with project satyr, you are hoping that attackers would access your honeypot proxies from their actual IP? I find that hard to believe. Most of them either use a reputed VPN or Tor as their first point of entry so you are just hoping for low hanging fruits here, which makes for a shitty threat intel


Not really, most DDoS attacks are made from servers, taking down those servers makes the attacker need to get new ones. And from the logs I can assure you that 90% of the time it is a server, and the rest it is either residential IPs or VPNs but residential IPs are seen more i'd say.


doesn't CF protect websites automatically from DDoS?


afaik meant to alert and mitigate, not protect. there are ddos attacks that get through cloudflare's lower tier plans


Yeah, many DDoS attacks get through cloudflare's lower tier plans, in fact bypassing cloudflare free is considered the bare minimum for a "stresser".


That’s literally what it’s there for


No, it is there to make money, if their free plan included perfect DDoS protection no one would get the more pricier ones.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: