Skip to content

Comment on Doxx/Darkflare: DarkFlare TCPoCDN (TCP over CDN)parent

Comments

I don’t get why headers and requests need to be spoofed if all traffic is over https?

Because the traffic is to a CDN endpoint (like Cloudflare) which expects it to be a HTTP message.

it can still be an https message, who cares what the path, query string, or headers look like? that is all encrypted

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.