{"id":13583445,"url":"https://github.com/jychp/cloudflare-bypass","last_synced_at":"2026-01-31T22:04:44.561Z","repository":{"id":48398452,"uuid":"351740849","full_name":"jychp/cloudflare-bypass","owner":"jychp","description":"Bypass Coudflare bot protection using Cloudflare Workers","archived":false,"fork":false,"pushed_at":"2021-07-27T19:34:12.000Z","size":11,"stargazers_count":779,"open_issues_count":5,"forks_count":112,"subscribers_count":23,"default_branch":"main","last_synced_at":"2024-07-30T14:17:45.209Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jychp.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-03-26T10:16:44.000Z","updated_at":"2024-07-15T08:34:13.000Z","dependencies_parsed_at":"2022-08-12T19:50:10.264Z","dependency_job_id":null,"html_url":"https://github.com/jychp/cloudflare-bypass","commit_stats":null,"previous_names":["jychp/cloudflare-bypass","resilience-jychp/cloudflare-bypass"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/jychp/cloudflare-bypass","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jychp%2Fcloudflare-bypass","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jychp%2Fcloudflare-bypass/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jychp%2Fcloudflare-bypass/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jychp%2Fcloudflare-bypass/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jychp","download_url":"https://codeload.github.com/jychp/cloudflare-bypass/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jychp%2Fcloudflare-bypass/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28956947,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-31T18:30:42.805Z","status":"ssl_error","status_checked_at":"2026-01-31T18:30:19.593Z","response_time":128,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T15:03:29.047Z","updated_at":"2026-01-31T22:04:44.546Z","avatar_url":"https://github.com/jychp.png","language":"JavaScript","funding_links":[],"categories":["JavaScript"],"sub_categories":[],"readme":"Bypass Cloudflare\n=================\n\n**DISCLAIMER: X-Forwarded-For has been patched by CloudFlare, but you can still use this script for proxy purpose**\n\n## General\n\nRelated to my Medium post: [How to bypass Cloudflare bot protection](https://jychp.medium.com/how-to-bypass-cloudflare-bot-protection-1f2c6c0c36fb)\n\n### Detailed operation\n* Step 1: You make your request to myproxy.tk, as we will correctly set our domain on CloudFlare, you can come from Tor or a public proxy without blocking.\n* Step 2: Your JS worker will forward the request, as you are already in the CloudFlare CDN, your request will be tagged (header + ip coming from CF) so you will bypass the CloudFlare security system\n\n### Important information\nAs usual, CF adds at least the following headers to your headers:\n * cf-connecting-ip: contains your real original IP\n * x-forwarded-for: IP string containing your original IP\n * and the original IP of the request is a CloudFlare IP\n \nWhen you go through the worker:\n * cf-connecting-ip: contains an IP of CF (probably the server where the Worker is running)\n * cf-worker: your domain name\n * and the original IP of the request is a CloudFlare IP\n \n**As you can see, your domain name appears in the headers. However it is a custom header, so few sites will log it or verify it, however beware of OPSEC.**\n\nYou will also notice that the x-forwarded-for is not present for a Worker, so you must define it, because a lot of sites (using CF tutorials) use this header instead of cf-connecting-ip to know your IP original.\n\nYou will therefore have understood that in addition if the site uses x-forwarded-for you can make the site believe that you come from any IP (nice for bypassing the security linked to the IP).\n\n## Set up\n### CloudFlare side\nFirst, you must have a domain for which you can change the DNS servers (a .tk domain works perfectly).\n\nOnce your CloudFlare account has been created and your servers configured, you will need to create at least one DNS entry, for example proxy.myproxy.tk to 1.2.3.4 in **proxyfied mode**. The IP is irrelevant because all traffic will be intercepted by the Worker.\n\nThen go to Firewall =\u003e Firewall Rules, and add the following rule:\n```\nField: Country\nOperator: equal to\nValue: Tor\nAction: ByPass (then select all security rules)\n```\nYou have just authorized any connection coming from Tor to connect to your domain without passing any control (therefore no blocking).\n\nThen go to Workers =\u003e Manage Workers =\u003e Create a Worker, copy the code from the * worker.js * file into it. **Remember to customize the TOKEN_HEADER, TOKEN_VALUE, HOST_HEADER and IP_HEADER values.**\n\nNow go to Workers =\u003e Manage Workers =\u003e Add route and configure the route:\n```\nItinéraire: proxy.myproxy.tk/*\nWorker: your_new_worker\n``` \nNB: You can also put `*.myproxy.tk/*` to capture all the subdomains.\n\nOpen https://proxy.myproxy.com in your browser, you should see the default page (\"Welcome to NGINX!\" By default.).\n\nNow you can attempt to modify your \"Host\" headers and the authent header and you should be able to see the page.\n\n\n### Python side\n\nStart by installing *requests* if you haven't already.\n\nThe script is simplistic, do not hesitate to complete it according to your needs. It will create a requests session, you can then use the get / post methods as with requests.\n\n\nExample\n```python3\n\u003e\u003e\u003e from cfproxy import CFProxy\n\u003e\u003e\u003e proxy = CFProxy('proxy.myproxy.tk', 'My Fucking User-Agent', '1.2.3.4')\n\u003e\u003e\u003e req = proxy.get('https://icanhazip.com')\n\u003e\u003e\u003e print(req.status_code)\n200\n\u003e\u003e\u003e print(req.text)\n108.162.229.50\n\n\u003e\u003e\u003e req = proxy.get('https://www.shodan.io')\n\u003e\u003e\u003e print(req.status_code)\n200\n\u003e\u003e\u003e print(req.text)\n[...]\n```\n\nBe careful, for your GET requests, put your parameters in a dict, and not in the URL:\n```python3\n# Bad Way\nproxy.get('https://domain.tld/index.php?id=1')\n# Good Way\npayload = {'id': 'mastring qui sera urlencore proprement'}\nproxy.get('https://domain.tld/index.php', params=payload)\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjychp%2Fcloudflare-bypass","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjychp%2Fcloudflare-bypass","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjychp%2Fcloudflare-bypass/lists"}