All great things are simple, and many can be expressed in single words: freedom, justice, honor, duty, mercy, hope

Friday, November 9, 2012

HOW TO FIND REAL I.P. PROTECTED BY CLOUD FLARE?

All these methods are based on bad admin configurations, but still are quite common

If you want to find real I.P. address of website, which is hidden by CLOUDFLARE. It has came to my attention that many booters, hosts, malicious websites, and more use CloudFlare for DDoS Protection & Anti-Abuse Report Protection. With CloudFlare protection, it is difficult to get the hosts IP; therefore, it is difficult to send an abuse report or launch a (D)DoS attack. This simple guide will help you obtain any website protected by CloudFlare's real IP, which can be used for whatever you desire!

METHOD 1:-

If you simply ping the domain , it will give i.p. which is not website`s real i.p. address. you should try following option to get real I.P. address of domain.

ping direct-connect.domain.com

             OR

ping direct.domain.com

             OR

ping ftp.domain.com

             OR

ping cpanel.domain.com

             OR

ping mail.domain.com

METHOD 2 :-

For a Long Aged Domain you can use netcraft toolbar to check real ip

For Example

Code:

http://toolbar.netcraft.com/site_report?url=DOMAIN.COM

Clearly We can see change in IP to a cloudflare one.

METHOD 3 :-

You can try bruteforcing DNS , some subdomain will have real IP of website.

For this purpose you need NMAP tools.

Open your terminal with root privellege & type following code

# nmap -sV -sS -F <target>

it will scan host & give results , it`s not give real i.p. of website.(but from this you can know weather website is protected by CLOUDFLARE or not)

Now type following code in terminal

# nmap --script dns-brute -sn <target>

it will give you real I.P. of website.


I made simple bash script which do all things for you.For more details click here.

Cloudflare-resolver

IF all of above methods does not work ;then there is no admin misconfiguration. So you cannot find real I.P.

22 comments:

Tiago Rocha said...

nothing work for me in this site "desirekal.com"
please help me send me e-mail...

Nirav Desai said...

Real i.p=91.205.40.12

mehroze malik said...
This comment has been removed by the author.
Nirav Desai said...

ajnabi.net is offline now, so i cannot find its Real i.p. :(@mehroze malik

mehroze malik said...

& pklover.net??

Nirav Desai said...

All these methods are based on bad admin configurations, if admin configuration is good ,then you can not find real i.p.@mehroze malik

ibraim reci said...

i need real ip pawn-shop.cc
and dardania.de ?

Nirav Desai said...

dardania.de=210.167.190.56@ibraim reci

asilas gaidys said...

HI ALL! pleas haelp me! What is IP adress of site http://erosx.lt? It says 188.165.227.84, but i dont understand it down, but website is on.. it is changed IP in another one no 188.165.227.84.

Nirav Desai said...

Ports are filtered, so it blocks your ping request.it allow only some specific i.p.@asilas gaidys

hani hanii said...

how can i find real IP for this website "jr7e.com"

Nirav Desai said...

reela i.p= 65.110.47.140@hani hanii

e2113334 said...

I would love to get the real IP of the website pa-mdh.me, please.

Thank you so much!!!!

Jose Soto said...

ip for arena-tournament.com ??
Please and thx!

Nirav Desai said...

188.165.14.13@Jose Soto

jeremiah pom said...

ip for pcworx.ph
thanks id advance

Nirav Desai said...

119.81.1.68@jeremiah pom

@Zerquix18 *-* said...

Thanks you! I got it with ftp.domain.com :)

xStorm Games said...

for ip jogar.miningbr.com?

bob said...

Thank you very much for your precious information however I couldn't manage to find real ip of coinad.com ... Could you please help me? Many thanks in advance!!

ixat.ca said...

if you can find http://zat.io real i,p you will be a god

ryan fuhrman said...

Could somebody get the real ip for waddleplus.com

Post a Comment

UA-35960349-1