CloudBleed with millions of sites (and SecNews)

CloudBleed is the unofficial name for a security issue that was discovered in 17 February of 2017 and hits Cloudflare reverse proxies.

For those who don't know Cloudflare is one of the biggest companies offering CDN, protection from DDOS, τεχνολογίες βελτιστοποίησης απόδοσης ιστοσελίδων, dedicated SSL και πολλά άλλα. Οι υπηρεσίες της Cloudflare χρησιμοποιούνται από περισσότερες από 5,5 εκατομμύρια ιστοσελίδες σύμφωνα με την εταιρεία. Το SecNews.gr είναι μια από αυτές.CloudBleed

The basic service is offered for free, but the , organizations and large companies can upgrade for additional features and better protection.

Το κενό ασφάλειας CloudBleed επέτρεπε στους servers να τρέχουν "past the end of a buffer" που επέστρεφε memory που περιείχε προσωπικές πληροφορίες. Μεταξύ των πληροφοριών αυτών είναι τα HTTP cookies, tokens, HTTP Post bodies, and other sensitive data.

The subject was revealed by a researcher Google Project Zero, and has already been defined by Cloudflare.

The problem for Internet users is that the cookies they use to link to these sites or other data may have leaked. Although the problem has been fixed, the search engines have temporary data stored, and the intruders could collect them.

Όταν η Google ανακοίνωσε στην Cloudflare την ευπάθεια, ειδοποίησε και άλλες μηχανές αναζήτησης προειδοποιώντας για καθάρισμα των cached αποτελεσμάτων αναζήτησης. Έτσι οι μηχανές αναζήτησης φέρεται να "ανακάτεψαν" τα cached δεδομένα, αλλά αυτό δεν σημαίνει ότι δεν υπάρχουν ακόμα ευαίσθητες πληροφορίες ελεύθερες στο δια.

It would be best to change passwords to all Cloudflare sites and services. This is of course not easy and it is rather time consuming to find out if the services and sites you visit use Cloudflare.

There is currently a list of one of his users GitHub   which displays all sites that use Cloudflare services. Some of them: Patreon, 4chan, Medium, Bitpay, News.ycombinator.com, uber.com, Yelp.com, uber.com and Greek Public.gr.

The online DoesItUseCloudflare it will also answer any of your questions about pages that you want to see if their data has leaked.

What about SecNews?

SecNews.gr visitors do not have to worry because they do not have any accounts on the site. The authors and administrators of the page, in addition to having already changed their passwords, use 2FA for each link on the site.

Visitors and members (who have an account) of large shopping websites using the CloudFlare service will need to change passwords immediately, and if they are given the ability to use two-factor authentication.

To easily check which pages are using Cloudflare you can use an add-on for Firefox and Chrome. The CloudBleed designed by the developer of NoSquint Plus, and will analyze your browser's browsing history to reveal any site page that Cloudflare uses.

This will allow you to find the pages considered dangerous data leakage and change your passwords.

Download the Add-on

Firefox

Chrome

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).