Ahh that makes more sense, especially if people aren't using the cf origin certs. I'd expect SNI to prevent this on newer systems though, unless it's the default cert on the ip.
I feel like this doesn't explain a lot. What makes it so trivial to find the origin? They just brush it aside as easy.
Also this really just comes back to: secure your origins folks, especially if you're relying on edge security features. Nobody should be relying on a waf though.
I printed some PETG clips for my outside railing to attach chicken wire (part of a catio). They've been fully exposed to the elements and sun for 2 years now, and aren't brittle yet.
They're pretty well known as massive maga funders