{"id":200272,"date":"2017-02-24T17:45:22","date_gmt":"2017-02-24T15:45:22","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=200272"},"modified":"2017-02-24T17:47:10","modified_gmt":"2017-02-24T15:47:10","slug":"cloudbleed-massive-bug-leaks-private-data-from-cloudflare","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/200272-cloudbleed-massive-bug-leaks-private-data-from-cloudflare.html","title":{"rendered":"Cloudbleed &#8211; Massive bug leaks private data from Cloudflare"},"content":{"rendered":"<p>Cloudflare said\u00a0a serious bug in its end servers caused private data to leak in response to clients requesting pages from Cloudlfare-protected sites.<\/p>\n<p>The leaked information included\u00a0HTTP cookies, authentication tokens, and HTTP POST bodies.<\/p>\n<p>&#8220;Some of that data had been cached by search engines,&#8221; said Cloudflare.<\/p>\n<p>The bug was caused by a buffer overrun which returned\u00a0the contents of memory in Cloudflare&#8217;s servers which it wasn&#8217;t meant to.<\/p>\n<p>Google&#8217;s Project Zero reported the issue to Cloudflare, and the two organisations worked to clean search engine caches before disclosing the vulnerability.<\/p>\n<p>&#8220;With the help of Google, Yahoo, Bing, and others, we found 770 unique URIs that had been cached and which contained leaked memory,&#8221; said\u00a0<strong><a href=\"https:\/\/blog.cloudflare.com\/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug\/\" target=\"_blank\">Cloudflare<\/a><\/strong>.<\/p>\n<p>&#8220;Those 770 unique URIs covered 161 unique domains.&#8221;<\/p>\n<p>Cloudflare said the earliest memory could have leaked\u00a0was 22 September 2016. The period of greatest impact was 13-18 February.<\/p>\n<p>Around 0.00003% of HTTP requests through Cloudflare potentially resulted\u00a0in memory leakage during that time.<\/p>\n<p>The timeline of the vulnerability was as follows:<\/p>\n<ul>\n<li><strong>2016-09-22:<\/strong> Automatic HTTP Rewrites enabled.<\/li>\n<li><strong>2017-01-30:<\/strong> Server-Side Excludes migrated to new parser.<\/li>\n<li><strong>2017-02-13:<\/strong> Email Obfuscation partially migrated to new parser.<\/li>\n<li><strong>2017-02-18:<\/strong> Google reports problem to Cloudflare and leak is stopped.<\/li>\n<\/ul>\n<p>Google&#8217;s Tavis Ormandy <strong><a href=\"https:\/\/bugs.chromium.org\/p\/project-zero\/issues\/detail?id=1139\" target=\"_blank\">posted several redacted examples<\/a><\/strong> of the leaked data online.<\/p>\n<p>These included data from Uber, Fitbit, and OK Cupid.<\/p>\n<p><a  data-lightbox=\"post-image\" href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/1892e622-8bfc-44fb-b7fa-6bcbafc7b71d.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-200284\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/1892e622-8bfc-44fb-b7fa-6bcbafc7b71d-640x272.png\" alt=\"Cloudbleed\" width=\"640\" height=\"272\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/1892e622-8bfc-44fb-b7fa-6bcbafc7b71d-640x272.png 640w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/1892e622-8bfc-44fb-b7fa-6bcbafc7b71d-600x255.png 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/1892e622-8bfc-44fb-b7fa-6bcbafc7b71d-768x326.png 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/1892e622-8bfc-44fb-b7fa-6bcbafc7b71d-1200x510.png 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/1892e622-8bfc-44fb-b7fa-6bcbafc7b71d.png 1845w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p><a  data-lightbox=\"post-image\" href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/83f96ae4-ec93-4625-8f28-722744186107.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-200282\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/83f96ae4-ec93-4625-8f28-722744186107-640x240.png\" alt=\"Cloudbleed\" width=\"640\" height=\"240\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/83f96ae4-ec93-4625-8f28-722744186107-640x240.png 640w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/83f96ae4-ec93-4625-8f28-722744186107-600x225.png 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/83f96ae4-ec93-4625-8f28-722744186107-768x288.png 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/83f96ae4-ec93-4625-8f28-722744186107-1200x449.png 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/83f96ae4-ec93-4625-8f28-722744186107.png 1365w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p><a  data-lightbox=\"post-image\" href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/1d77504c-8b0f-48d0-91f6-d6dde88fe4c0.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-200280\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/1d77504c-8b0f-48d0-91f6-d6dde88fe4c0-462x430.png\" alt=\"Cloudbleed\" width=\"462\" height=\"430\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/1d77504c-8b0f-48d0-91f6-d6dde88fe4c0-462x430.png 462w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/1d77504c-8b0f-48d0-91f6-d6dde88fe4c0-430x400.png 430w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/1d77504c-8b0f-48d0-91f6-d6dde88fe4c0-768x714.png 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/02\/1d77504c-8b0f-48d0-91f6-d6dde88fe4c0.png 1173w\" sizes=\"(max-width: 462px) 100vw, 462px\" \/><\/a><\/p>\n<h3 class=\"my-4\">Now read:\u00a0<a href=\"http:\/\/mybroadband.co.za\/news\/security\/103735-new-bugs-found-in-software-that-caused-heartbleed-cyber-threat.html\">New bugs found in software that caused &#8220;Heartbleed&#8221; cyber threat<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Cloudflare said a serious bug in its end servers caused private data to be leaked online.<\/p>\n","protected":false},"author":23,"featured_media":200274,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[41582,29694,167,26080],"class_list":["post-200272","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cloudbleed","tag-cloudflare","tag-google","tag-google-project-zero"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/200272"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=200272"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/200272\/revisions"}],"predecessor-version":[{"id":200288,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/200272\/revisions\/200288"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/200274"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=200272"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=200272"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=200272"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}