Cloudbleed - Cloudflare's Memory Leak

Discussion in 'Industry News' started by PixelButts, Feb 24, 2017.

  1. PixelButts

    PixelButts Site Soldier

    Joined:
    Aug 19, 2014
    Messages:
    2,665
    Likes Received:
    1,808
    To make it simple I'll copy and paste the github summary (https://github.com/pirate/sites-using-cloudflare)

    "Between 2016-09-22 - 2017-02-18 passwords, private messages, API keys, and other sensitive data were leaked by Cloudflare to random requesters. Data was cached by search engines, and may have been collected by random adversaries over the past few months.

    Requests to sites with the HTML rewrite features enabled triggered a pointer math bug. Once the bug was trigerred the response would include data from ANY other cloudfare proxy customer that happened to be in memory at the time. Meaning a request for a page with one of those features could include data from Uber or one of the many other customers that didn't use those features. So the potential impact is every single one of the sites using CloudFare's proxy services (including HTTP & HTTPS proxy)."

    I have spoken to @Demon and his 2 sites have been affected and are on the list as well as a friend of his and his domain.

    Please refer to this list to check if there is any site you access or own that has been affected by this.
    https://github.com/pirate/sites-using-cloudflare/archive/master.zip (the txt is 63mb, please use notepad++ if on windows to open this and search, notepad will not help you)

    I advise everyone to proceed with caution, and do your best to ensure your sensitive data is safe
     
  2. D_Ban

    D_Ban Robust Member

    Joined:
    Aug 11, 2008
    Messages:
    289
    Likes Received:
    348
    Really annoyed by this. Had to change passwords for those sites of mine and inform the users.

    Noticed a bunch of sites from friends on there from researching more. Unreal how they can allow something like this to happen.

    Thankfully no private info of my sites seems to have been disclosed but better to change passes to be safe.

    EDIT: While my site was on the list it seems I wasn't compromised as I just got this email,

     
    Last edited: Feb 24, 2017
  3. Syclopse

    Syclopse .

    Joined:
    Dec 17, 2013
    Messages:
    1,508
    Likes Received:
    537
    system likes this.
  4. PixelButts

    PixelButts Site Soldier

    Joined:
    Aug 19, 2014
    Messages:
    2,665
    Likes Received:
    1,808
  5. Syclopse

    Syclopse .

    Joined:
    Dec 17, 2013
    Messages:
    1,508
    Likes Received:
    537
    Only if it's plugged in to the interwebs, otherwise you're good.
     
sonicdude10
Draft saved Draft deleted
Insert every image as a...
  1.  0%

Share This Page