> For the complete documentation index, see [llms.txt](https://0xpthree.gitbook.io/notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://0xpthree.gitbook.io/notes/network-services/ports/80-443-http-s/web-vulnerabilities/cloudflare-bypass.md).

# CloudFlare Bypass

### Techniques

* You can also use some service that gives you the **historical DNS records** of the domain. Maybe the web page is running on an IP address used before.
  * Same could be achieve **checking historical SSL certificates** that could be pointing to the origin IP address.
  * Check also **DNS records of other subdomains pointing directly to IPs**, as it's possible that other subdomains are pointing to the same server (maybe to offer FTP, mail or any other service).
* If you find a **SSRF inside the web application** you can abuse it to obtain the IP address of the server.
* Use Google cache: `https://webcache.googleusercontent.com/search?q=cache:https://www.petsathome.com/shop/en/pets/dog`
* Use other cache services such as <https://archive.org/web/>
