[ALERT] CloudFlare vulernability | #Cloudbleed HTTPS Traffic Leak

Posts 14 of 4 · Page 1 of 1
[ALERT] CloudFlare vulernability | #Cloudbleed HTTPS Traffic Leak
Source from *******: Liberal clam(Programmix#0748)

Just a heads up of a recently exposed vulnerability within CloudFlare's infrastructure. The vulnerability pertains to data exposure during transmission between CloudFlare's proxy servers and the target server. This has been the case for data transferred between 2016-09-22 and 2017-02-18.

*******'s Aethex developer, 'Liberal clam' made the announcement on his server within the hour of this post.
Passwords should be changed on all sites using CloudFlare.

******* itself is listed as an affected site, but ******* confirmed that they are unlikely to have been affected as they do not use the features of CloudFlare that were vulnerable. But your password should be changed anyway, just for safety.

Affected sites and more information can be found in this list:
https://github.com/pirate/sites-using-cloudflare

Liberal's sources:
https://bugs.chromium.org/p/project-zero...il?id=1139
https://blog.cloudflare.com/incident-rep...arser-bug/
https://www.reddit.com/r/sysadmin/commen...e_reverse/

Edit | Some interesting news articles have popped up:
https://www.theregister.co.uk/2017/02/24...onal_data/
https://medium.com/@octal/cloudbleed-how....ahn7wcd5a
https://www.lifehacker.com.au/2017/02/cl...-affected/
https://www.privateinternetaccess.com/bl...t-history/
Thanks for a consolidated view.

MPGH isn't listed in the top 10,000 websites that were affected. (whew)
Quote Originally Posted by arunforce View Post
Thanks for a consolidated view.

MPGH isn't listed in the top 10,000 websites that were affected. (whew)
http://www.mpgh.net/forum/showthread.php?t=1230290

Quote Originally Posted by Cinodor View Post
Thanks for the information, I'll make sure to update LastPass with new ones.

Also MPGH is on the list
:/
Posts 14 of 4 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?