That is EXACTLY how this works. A secure setup would make the origin server reject all requests from non-cloudflare IPs but this needs to be configured. Cloudflare even provides examples on how to get and update that list of IPs. Most admins are too lazy or incompetent to do this or do not understand the risk.
That is EXACTLY how this works. A secure setup would make the origin server reject all requests from non-cloudflare IPs but this needs to be configured. Cloudflare even provides examples on how to get and update that list of IPs. Most admins are too lazy or incompetent to do this or do not understand the risk.