- Jun 2, 2009
- 5,312
- 1,750
- 136
A huge security issue has been found in cloudflare.
See
Bug Report
Reddit Thread
Expect media to soon jump on this as they should. The leak is so bad basically a global password and private key reset is required if you want to be 100% sure.
Specific cloudflare services randomly leaked memory from other requests to cloud flare. Could be anything from password, to ssl private keys, sensitive messages and so forth. Really, really bad.
The problem this data is then put into the web page (hidden, user can't directly see it) but is stored in caches for example google cache (they are trying to delete everything), archive sites, other search engines and users web cache. So a random person in Russia might have your password stored in his browser cache...
See
Bug Report
Reddit Thread
Expect media to soon jump on this as they should. The leak is so bad basically a global password and private key reset is required if you want to be 100% sure.
The examples we're finding are so bad, I cancelled some weekend plans to go into the office on Sunday to help build some tools to cleanup. I've informed cloudflare what I'm working on. I'm finding private messages from major dating sites, full messages from a well-known chat service, online password manager data, frames from adult video sites, hotel bookings. We're talking full https requests, client IP addresses, full responses, cookies, passwords, keys, data, everything.
Specific cloudflare services randomly leaked memory from other requests to cloud flare. Could be anything from password, to ssl private keys, sensitive messages and so forth. Really, really bad.
The problem this data is then put into the web page (hidden, user can't directly see it) but is stored in caches for example google cache (they are trying to delete everything), archive sites, other search engines and users web cache. So a random person in Russia might have your password stored in his browser cache...