Thats what I was thinking their method was 'like'
Blocking Cloudflare IPs on servers EXCEPT where specifically needed is a good idea.
SAMEORIGIN would not help in this scenario.
Cloudflare needs to police their clients better -- copyright infringement and fraud most likely are Cloudflare TOS violations.
Thanks for looking into this Konrad.
BTW a 302 -301 domain redirection will work -- maybe even a page redirection -- this is working for lifeselector -- planed or not.
|