Hacker News new | ask | show | jobs
by jaywalk 2290 days ago
Took me a second to wrap my head around what you were saying, so I'll point it out: they'd be pointing their CDN account to your origin server, and making requests through it.
1 comments

Same for Cloudflare - to mitigate this your server should only respond to the correct HOST header for your website.