{"id":18021211,"url":"https://github.com/yousefvand/wlcf","last_synced_at":"2026-04-13T12:01:55.960Z","repository":{"id":96625594,"uuid":"150016640","full_name":"yousefvand/wlcf","owner":"yousefvand","description":"Whitelist Cloudflare network","archived":false,"fork":false,"pushed_at":"2018-09-24T11:03:20.000Z","size":3,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-08-14T00:27:08.134Z","etag":null,"topics":["cloudflare","ddos","ip","linux","port-scanning","shell-script","whitelist"],"latest_commit_sha":null,"homepage":null,"language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/yousefvand.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2018-09-23T19:10:08.000Z","updated_at":"2020-10-10T10:13:09.000Z","dependencies_parsed_at":"2023-03-14T16:15:34.186Z","dependency_job_id":null,"html_url":"https://github.com/yousefvand/wlcf","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/yousefvand/wlcf","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yousefvand%2Fwlcf","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yousefvand%2Fwlcf/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yousefvand%2Fwlcf/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yousefvand%2Fwlcf/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/yousefvand","download_url":"https://codeload.github.com/yousefvand/wlcf/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yousefvand%2Fwlcf/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":31751705,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-13T09:16:15.125Z","status":"ssl_error","status_checked_at":"2026-04-13T09:16:05.023Z","response_time":93,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cloudflare","ddos","ip","linux","port-scanning","shell-script","whitelist"],"created_at":"2024-10-30T06:09:08.130Z","updated_at":"2026-04-13T12:01:55.913Z","avatar_url":"https://github.com/yousefvand.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Whitelist Cloudflare network IPs\n\nAfter moving to [Cloudflare](https://www.cloudflare.com/) CDN service, all requests to your server will be proxied through Cloudflare. That's how Cloudflare protects your server from [DoS](https://en.wikipedia.org/wiki/DOS) and [DDoS](https://en.wikipedia.org/wiki/Denial-of-service_attack).\n\nSo after migrating to Cloudflare you need to change your server IP and keep it confidential. Most probably you won't change your data-center and attackers would scan data-center IP ranges to find your new server IP. Even if you use an IP from a completely different range, finding you is still feasible with the right tools in few days.\n\nTo protect your server you need to hide any fingerprint and be just visible to Cloudflare network. It means even SSH port should not be detectable via port scanning.\n\nThis bash script automatically Whitelists [official Cloudflare IP ranges](https://www.cloudflare.com/ips/) and hide your SSH port by [port knocking](https://en.wikipedia.org/wiki/Port_knocking).\n\n**IMPORTANT:** Here port knocking is not used for securing your SSH connection, and you should do that by using strong password and [public key authentication](https://www.ssh.com/ssh/key/).\n\n## Usage\n\n```bash\nbash wlcf.sh\n```\n\nScript will generate `client.sh` which you can use on client machine for stablishing SSH connections to your server.\n\nWithout knowing the right sequence of ports, you are completely invisible to outside world.\n\n### Tested on Ubuntu server 16.04/18.04","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fyousefvand%2Fwlcf","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fyousefvand%2Fwlcf","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fyousefvand%2Fwlcf/lists"}