In fact, some mainstream websites, including Cloudflare, can detect this, and you can also report it to Cloudflare, they will send warning message to the potential abuser.
🧵 Thread:
小白今天才知道:原来利用Cloudflare Worker 反向代理实时抓取,就可以一比一复刻一个网站了 🥲就是所谓的镜像站
然后你可以通过 cf.worker.upstream_zone 识别并拦截所有外部 Worker 请求,就可以从源头让这类镜像站失效
Thanks, really appreciate this. I hadn’t actually thought of handling it through an abuse report to Cloudflare. Makes sense that once a phishing report comes in, the workers .dev URL gets restricted pretty quickly, like in your screenshot. Good to know that’s an option.
@https1024
🧵 Thread:
小白今天才知道:原来利用Cloudflare Worker 反向代理实时抓取,就可以一比一复刻一个网站了 🥲就是所谓的镜像站
然后你可以通过 cf.worker.upstream_zone 识别并拦截所有外部 Worker 请求,就可以从源头让这类镜像站失效
Thanks, really appreciate this. I hadn’t actually thought of handling it through an abuse report to Cloudflare. Makes sense that once a phishing report comes in, the workers .dev URL gets restricted pretty quickly, like in your screenshot. Good to know that’s an option.
@https1024