Let’s say we are targeting carabinersec.com and we want to DoS or DDoS attacks on it.

However, if WAF is blocking us, we won’t be able to do so.

By discovering the original IP address that is not under WAF, we should be able to conduct DoS attack.

Here are hackerone reports about this bug:

Identify WAF

First, try to ping the domain:

┌──(carabiner1㉿carabiner)-[~]
└─$ ping yahoo.com
PING yahoo.com (74.6.231.20) 56(84) bytes of data.
64 bytes from media-router-fp73.prod.media.vip.ne1.yahoo.com (74.6.231.20): icmp_seq=1 ttl=128 time=364 ms
64 bytes from media-router-fp73.prod.media.vip.ne1.yahoo.com (74.6.231.20): icmp_seq=2 ttl=128 time=389 ms
64 bytes from media-router-fp73.prod.media.vip.ne1.yahoo.com (74.6.231.20): icmp_seq=3 ttl=128 time=306 ms
^C
--- yahoo.com ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2001ms
rtt min/avg/max/mdev = 305.683/352.881/388.834/34.865 ms

We can see that the IP address is exposed.

Try copy-pasting the IP address to any browser. We will get error.

This might happen because the website is behind cloudfare WAF.

Now let’s try to discover the original IP.

Discover Original IP

Using the various methods below, collect IP addresses from the domain.

Tool/ServiceURLQuery Example
Shodanhttps://www.shodan.iossl.cert.subject.CN:"*.yahoo.com" 200
Censyshttps://search.censys.io/"yahoo.com"
Fofahttps://fofa.so"yahoo.com"
SecurityTrailshttps://securitytrails.com/"yahoo.com"
NSLookuphttps://nslookup.ioN/A
CompleteDNShttps://completedns.com/N/A
ZoomEyehttps://zoomeye.hkN/A
VirusTotalhttps://virustotal.comN/A
Netlashttps://netlas.ioN/A
DNSHistoryhttps://dnshistory.org/N/A
IPLocationhttps://iplocation.netN/A
IntoDNShttps://intodns.comN/A
IPVoidhttps://ipvoid.comN/A
Whoishttps://who.isN/A
DNSWatchhttps://dnswatch.infoN/A
ViewDNShttps://viewdns.infoN/A
DNSCheckerhttps://dnschecker.orgN/A

After collecting all the IP addresses, use httpx for live IP address and use aquatone for screenshots:

cat collected-ip.txt | httpx | aquatone

Automation

Instead, we can automate it: