NexusFi: Find Your Edge


Home Menu

 





Cloudfare Leak


Discussion in Traders Hideout

Updated
    1. trending_up 2,067 views
    2. thumb_up 4 thanks given
    3. group 1 followers
    1. forum 1 posts
    2. attach_file 0 attachments




 
Search this Thread

Cloudfare Leak

  #1 (permalink)
 
tturner86's Avatar
 tturner86 
Portland, Oregon
 
Experience: Intermediate
Platform: F-16CM-40
Trading: GBU-39
Posts: 6,191 since Sep 2013
Thanks Given: 10,459
Thanks Received: 12,695

A huge memory leak was found in the CDN/DNS giant CloudFare's Parser service. Potential information that could've been stolen includes, but is not limited to Passwords, Private Messages, API Keys, IP Addresses, and more between Sept. 22nd 2016 and Feb. 18th 2017. Information was available to random requesters due to the exploit, some even being cached by Search Engines such as Google, meaning advertising companies and anyone who happened to come across it could've picked it up. An estimated 100,000 to 200,000 paged requests of private data was leaked between Feb 13th to Feb 18th per day.

It is highly recommended that you change passwords on the affected sites, if not all passwords. You should also be using Two-Factor Authentication wherever possible.

Popular Affected Websites
- discordapp.com
- reddit.com
- 1password.com (response: https://blog.agilebits.com/2017/02/23/three-layers-of-encryption-keeps-you-safe-when-ssltls-fails/)
- authy.com
- digitalocean.com
- patreon.com
- bitpay.com
- stackoverflow.com
- 4chan.org
- yelp.com
- uber.com

and 7,385,121 other potentially affected websites
List: https://github.com/pirate/sites-using-cloudflare

For a more in-depth technical description of this exploit, see the following blog post below:
https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/

The bug report on Project Zero
https://bugs.chromium.org/p/project-zero/issues/detail?id=1139

Visit my NexusFi Trade Journal Started this thread Reply With Quote
Thanked by:

Can you help answer these questions
from other members on NexusFi?
PowerLanguage & EasyLanguage. How to get the platfor …
EasyLanguage Programming
How to apply profiles
Traders Hideout
Better Renko Gaps
The Elite Circle
MC PL editor upgrade
MultiCharts
REcommedations for programming help
Sierra Chart
 
Best Threads (Most Thanked)
in the last 7 days on NexusFi
Just another trading journal: PA, Wyckoff & Trends
31 thanks
Spoo-nalysis ES e-mini futures S&P 500
28 thanks
Tao te Trade: way of the WLD
24 thanks
Bigger Wins or Fewer Losses?
20 thanks
GFIs1 1 DAX trade per day journal
17 thanks




Last Updated on February 24, 2017


© 2024 NexusFi™, s.a., All Rights Reserved.
Av Ricardo J. Alfaro, Century Tower, Panama City, Panama, Ph: +507 833-9432 (Panama and Intl), +1 888-312-3001 (USA and Canada)
All information is for educational use only and is not investment advice. There is a substantial risk of loss in trading commodity futures, stocks, options and foreign exchange products. Past performance is not indicative of future results.
About Us - Contact Us - Site Rules, Acceptable Use, and Terms and Conditions - Privacy Policy - Downloads - Top
no new posts