Makes me wonder if the Great Firewall has a caching layer.
Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
721–730 of 1001 posts
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#722Earlier quoted context omitted.
> edit: why the revulsion I'd guess it's because of the crude and reductive way you describe the service cloudflare provides. I don't know what type of programming you do, but many small services don't have the infrastructure to mitigate the kind of attacks cloudflare deals with and they wouldn't be around without services like this. I don't like the internet becoming centralized into a few small places that mitigate…
How about... stop CLOUD THIS and CLOUD THAT. Cloud means extreme centralization. It means giving your data to a third party you don't control. Why? Why does our networked software have to assume a centralized topology? In the days when developed countries had dialup, protocols (IRC, Email, etc.) were all decentralized. Today, all the famous developers live with fancy broadband internet connections and forgot what it'…
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#723Earlier quoted context omitted.
It is far from over, too! Google Cache still has loads of sensitive information, a link away! Look at this, click on the downward arrow, "Cached": https://www.google.com/search?q="CF-Host-Origin-IP:"+"author... (And then, in Google Cache, "view source", search for "authorization".) (Various combinations of HTTP headers to search for yield more results.)
It seems like the reasonable thing for Google to do is to clear their entire cache. The whole thing. This is the one thing that they could do to be certain that they aren't caching any of this.
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#724Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#725Can we start a list of affected right now? I found: OKCupid Uber people claiming 1Password, can't find Reddit Lyft Yelp Pingdom Digital Ocean Montecito Bank and Trust
Patreon 4chan used to use it apparently, don't know if affected kik Zoho CRM change.org Cloudflare itself, of course Feedly
According to doesitusecloudflare.com Zoho isn't using Cloudflare, was it previously?
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#726Earlier quoted context omitted.
If I'm understanding correctly, that list would include not only the 3,438 domains with content that triggered the bug, but every Cloudflare customer between 2016-09-22 and 2017-02-18.
Can we trust it was only those domains?
And of course all other sites that are not in alexa 10k are not in this list (if they are not on some other lists used, you can see the source of lists in the README of the Github repo).
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#727Earlier quoted context omitted.
I would say the crazy thing is a mere t-shirt as their "bug bounty" top tier award given how they've pitched themselves as an extremely secure service. https://hackerone.com/cloudflare I'm sorry but when the reward for breaking into you is basically a massive pinata of personal information...that simply is a bad joke. Security flaws are going to happen and if you aren't going to even offer a reasonable financial rewa…
Nah. Bug bounties don't work for services like CDNs. Maybe they do elsewhere. But for enterprise services, the noise rate is too high, and the very good bug finders are either salaried, free, or working for the adversary.
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#728Holy sh*t. Is this the end of Cloudflare with the trust being absolutely destroyed and lawsuits coming in? Can't say I'm sad for them. Cloudflare sells you DDOS protection, and hosts (eg. masks the IP of) the very DDOSers to protect against themselves, which I find bordering on the criminal. Hosters like Hetzner, OVH have for a year now offered DDOS protection (I'm guessing it's heuristic rate limiting, but they won'…
A while later, we figured out how to reproduce
the problem. It looked like that if an html page
hosted behind cloudflare had a specific
combination of unbalanced tags,
[...]
The leakage was the result of a bug in an HTML
parser chain Cloudflare uses to modify Web pages
as they pass through the service's edge servers.
Ahem, at the risk of sounding pedantic, but this wouldn't have happened when using a proper HTML/SGML parser ([1]).Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#729"We were working to disclose the bug as quickly as possible, but wanted to clean up search engine caches before it became public because we felt we had a duty of care to ensure that this private information was removed from public view. We were comfortable that we had time as Google Project Zero initially gave us a 90 day disclosure window (as can still be seen in their incident tracker), however after a couple of days, they informed us that they felt that 7 days was more appropriate. Google Project Zero ended up disclosing this information after only 6 days."