National Cyber Warfare Foundation (NCWF)

Inside cdn-ip-scanner: how it maps fast CDN edge IPs with five-attempt verification


0 user ratings
2026-09-27 03:29:54
milo
Red Team (CNA)
"Inside

A Flask and Socket.IO web application that discovers low-latency Cloudflare and Fastly edge IPs via multithreaded scanning, built for network performance analysis in authorized environments.








Toolshahinst/cdn-ip-scanner — web-based scanner that finds fast, low-latency CDN IP addresses from providers like Cloudflare and Fastly
CategoryNetwork reconnaissance / CDN performance analysis (Python, Flask, WebSocket)
Primary UseDiscovering responsive, low-latency CDN edge IPs using /cdn-cgi/trace verification, with filtering by ping range and open ports
Safe UseIntended for authorized network performance testing, lab environments, and legitimate CDN connectivity research on infrastructure you are permitted to assess; treat any deployment as a self-hosted instrument, not an attack tool.
Telemetry NoteEvery probe hits the CDN's /cdn-cgi/trace endpoint, so providers observe bursts of HTTP requests from the scanner's source IP; scanning generates heavy TCP connection volume that is trivially visible in flow logs and rate-limit telemetry, and self-hosted instances log activity to journalctl via systemd.

cdn-ip-scanner positions itself as a web-based utility for a problem that is genuinely tedious by hand: identifying which IP addresses inside a CDN's published ranges actually respond well from your vantage point. The tool targets Cloudflare, Fastly, and other providers, fetching their announced ranges from multiple sources — the Cloudflare API, ASN data, GitHub-hosted lists, and Fastly's verified list — and then probing candidates to find clean, low-latency addresses. At roughly 113 stars and written in Python, it is a single-repo Flask application you can run on a laptop or deploy on a Linux server. The framing is performance measurement rather than exploitation, which shapes how it should be read.


The core validation logic is what the README leans on hardest: a five-attempt verification method. Each candidate IP is tested five times with connection reuse against the /cdn-cgi/trace endpoint, and a minimum of three out of five successes is required before the IP is reported. This is a sensible design choice for anyone who has done this kind of work manually — single-probe results are noisy, and transient packet loss produces false positives. By demanding repeated, sustained responsiveness, the tool filters out flaky edges and reports only genuinely usable addresses. The /cdn-cgi/trace endpoint itself is the standard Cloudflare diagnostic path, which makes it a reasonable liveness and latency probe.


Internally, the architecture is a conventional but well-organized Flask stack. The backend uses Python 3, Flask, Flask-SocketIO, and gevent, with scanning parallelized through ThreadPoolExecutor. Results stream to the browser in real time over Socket.IO WebSocket rather than requiring page refreshes, which matters when a scan is producing hits continuously. Persistence goes to SQLite by default with MySQL/MariaDB as options, and the project tree in the README shows clean separation: app/scanner/core.py holds the scan engine, range_fetcher.py handles multi-source range acquisition, operators.py defines ISP data, v2ray.py handles config parsing, and ai_optimizer.py implements the sampling logic.


That last module deserves scrutiny because 'AI Powered' appears prominently in the README banner. Based on the feature table, the intelligence here is smart IP sampling and range prioritization — heuristic ordering of which subranges to probe first so that working IPs surface faster — not a learned model in any meaningful sense. That is fine; sampling heuristics are the right engineering answer to scanning enormous /12-style CDN blocks with bounded resources. But operators evaluating the tool should calibrate expectations: the 'AI' is an optimization layer over a brute-force probe loop, not a prediction system.


Resource control is handled through four named speed modes: Hyper at 20%, Turbo at 40%, Ultra at 60%, and Deep at 80%, expressed as a percentage of available capacity. This granularity is practical for running the scanner on shared infrastructure where a full-bore thread pool would saturate the uplink. The README also advertises a responsive stop button that halts a scan within two seconds — a small detail, but one that signals the authors have actually run this on constrained connections and gotten feedback from users who needed to abort mid-scan.


Three scan methods are offered. Cloud Scan is direct CDN IP scanning with a TCP pre-filter followed by the five-attempt HTTP verification. Operator Scan tests which CDN IPs perform best against specific ISPs — the README names Iranian operators (Irancell, MCI, Rightel, Shuttle) plus Chinese and Russian ones, which tells you a lot about the tool's primary user base: regions where CDN fronting performance varies dramatically by carrier. The third, V2Ray Scan, parses vless://, vmess://, and trojan:// configuration strings and tests candidate IPs against them with automatic IP replacement. This is clearly the feature that drives adoption, and it sits squarely in censorship-circumvention territory rather than offensive security.


The V2Ray support is worth a candid note for a professional audience: the tool itself only performs reachability and latency testing against proxy configs the user supplies. It does not generate configs, host infrastructure, or embed payloads. Still, readers should understand the context — this class of tool is predominantly used to keep personal proxy setups working in censored networks, and any security team evaluating it should classify it accordingly, as a network diagnostics instrument with a circumvention-adjacent user community, not as a pentest weapon.


Deployment is where the README gets most detailed. On Linux, an interactive install.sh detects the distribution across Ubuntu, Debian, CentOS, RHEL, Rocky, Alma, and Fedora, then provisions a fairly complete stack: Nginx as a reverse proxy with HTTP Basic Auth, SSL via Let's Encrypt for domains or self-signed certs for bare IPs, a systemd unit for boot persistence, and firewall rules opening ports 80 and 443. Post-install management uses standard systemctl status cdn-ip-scanner and journalctl -u cdn-ip-scanner -f, with an uninstall.sh for cleanup. Windows users get a standalone CDN-IP-Scanner.V2.0.Windows.zip executable requiring no Python; macOS ships as a build kit running build.sh.


For a manual source deployment, the path is minimal — clone the repo, create a python3 -m venv venv, activate it, pip install -r requirements.txt, and launch python run.py --port 8080. Notably, the packaged installer's decision to put Basic Auth and TLS in front of the panel by default is good hygiene for a web-accessible scanner; anyone hand-rolling the run.py route should replicate that protection themselves, since an unauthenticated scanning panel on a public IP is an abuse waiting to happen.


The results workflow is fully instrumented for downstream use: exports to JSON, Excel via openpyxl with .xlsx output, or plain-text IP-only lists, plus filtering by ping range and specific open ports before export. There is a real-time scan log with a DEBUG mode for troubleshooting, an in-app auto-updater that pulls new releases directly, and a UI localized across English, Persian, Chinese, and Russian with dark and light themes. The multilingual investment again reflects who actually uses this tool day to day.


From a defensive perspective, the telemetry footprint is significant and easy to observe. The scanner's probes are ordinary HTTP requests to /cdn-cgi/trace across wide IP ranges, which shows up as distinctive request bursts against any provider's rate limiting, and the TCP pre-filter stage generates high-volume connection attempts visible in flow data. Corporate SOC teams seeing this pattern from an internal host are most likely looking at an employee chasing better CDN latency for a personal proxy, not an active intrusion — but it is worth a conversation, because the behavior is indistinguishable at the network layer from reconnaissance of CDN address space and should be policy-checked like any scanning tool.


Overall, cdn-ip-scanner is a competently engineered niche tool: honest about its method, well documented in four languages, with an installer that takes operational security seriously. For authorized network engineers, CDN performance researchers, and red-team infrastructure maintainers who need reliable edge-IP discovery in their own environments, the five-attempt verification model and multi-source range fetching make it one of the more rigorous options in this category. Treat it as measurement infrastructure, deploy it behind authentication, and be aware of the network noise it generates whenever you run it.



Official project repository for shahinst/cdn-ip-scanner.

Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.






Source: OffensiveSec
Source Link: https://www.offsecblog.com/2026/09/inside-cdn-ip-scanner-how-it-maps-fast.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.