CloudBleed είναι το ανεπίσημο name για ένα ζήτημα ασφαλείας που ανακαλύφθηκε στις 17 Φεβρουαρίου του 2017 και πλήττει τα reverse Cloudflare proxies.
For those who do not know Cloudflare is one of the largest companies offering CDN, protection against DDOS attacks, web page optimization technologies, dedicated SSL and more. Cloudflare services are used by more than 5,5 million websites according to the company. SecNews.gr is one of them.
Basic service is offered for free, but webmasters, organizations and large companies can upgrade for additional features and better protection.
The gap better safetyς CloudBleed επέτρεπε στους servers να τρέχουν “past the end of a buffer” που επέστρεφε memory που περιείχε προσωπικές πληροφορίες. Μεταξύ των πληροφοριών αυτών είναι τα HTTP cookies, authentication tokens, HTTP Post bodies, και άλλα ευαίσθητα δεδομένα.
The subject was revealed by a researcher Google Project Zero, and has already been defined by Cloudflare.
The problem for Internet users is that the cookies they use to connect to these sites or other data may have been leaked. Although the problem has been fixed, the machines searchs have temporary data stored, and attackers could collect it.
Όταν η Google ανακοίνωσε στην Cloudflare την ευπάθεια, ειδοποίησε και άλλες μηχανές αναζήτησης προειδοποιώντας για καθάρισμα των cached αποτελεσμάτων αναζήτησης. Έτσι οι μηχανές αναζήτησης φέρεται να “ανακάτεψαν” τα cached δεδομένα, αλλά αυτό δεν σημαίνει ότι δεν υπάρχουν ακόμα ευαίσθητες πληροφορίες ελεύθερες στο Internet.
It would be best to change passwords to all Cloudflare sites and services. This is of course not easy and it is rather time consuming to find out if the services and sites you visit use Cloudflare.
There is currently a list of one of his users GitHub which displays all sites that use Cloudflare services. Some of them: Patreon, 4chan, Medium, Bitpay, News.ycombinator.com, uber.com, Yelp.com, uber.com and Greek Public.gr.
That's it online tool DoesItUseCloudflare it will also answer any of your questions about pages that you want to see if their data has leaked.
What about SecNews?
SecNews.gr visitors do not have to worry because they do not have any accounts on the site. The authors and administrators of the page, in addition to having already changed their passwords, use 2FA for each link on the site.
Επισκέπτες και μέλη (όσοι διαθέτουν λογαριασμό) μεγάλων ιστοσελίδων αγορών που χρησιμοποιούν την υπηρεσία CloudFlare, θα πρέπει να αλλάξουν άμεσα κωδικούς πρόσβασης, και αν τους δίνεται η δυνατότητα να χρησιμοποιήσουν έλεγχο ταυτότητας two factors.
To easily check which pages are using Cloudflare you can use an add-on for Firefox and Chrome. The CloudBleed designed by the developer of NoSquint Plus, and will analyze your browser's browsing history to reveal any site page that Cloudflare uses.
This will allow you to find the pages considered dangerous data leakage and change your passwords.
Download the Add-on
