Cloudflare Botfight and DNS

RATE MY SETUP:

  1. Modify evilginx source code so Cloudflare botfight and WAF load balancers are not blocked (sed -i ‘s_proxyHeaders := string{"&CF-Connecting-IP", "’ evilginx2/core/http_proxy.go)

  2. Set up “@” and subdomain-specific cloudflare DNS records pointing to my droplet IP (Cloudflare proxy off)

  3. Enable phishlet (with autocert on, blacklist unauth, established hostname and hidden phishlet)

  4. In cloudflare, go to SSL/TLS>Overview>SSL/TLS Encryption>Configure and set it to Full (or Full Strict ← NOT SURE)

  5. Go to cloudlfare DNS, set cloudflare proxy on

if u using private or origin certifcate from cloudflare then use strict mode and in that case only u can enable loudflare proxy on a name records .

So I should only use strict mode if origin certificate is issued? For just BotFIght and WAF I can set SSL/TLS encryption to full instead of full strict?

@fluxxset please i need your attention

strict Mode and enable proxy on A name reccords

How can i help, msg me