ALERT! Wide Impact: Cloudflare Data Leak. How to Secure your Site

Danielx64

Developer
Joined
Nov 8, 2009
Messages
3,300
This email came in about 15 mins ago:

This is an unscheduled announcement that we are sending this evening to address an urgent issue which became public a few hours ago. There has been a serious data leak that affects all Cloudflare customer websites and their site visitors.

It was just announced that for the past 5 months, in certain cases sensitive data being sent from a Cloudflare customer website to a site visitor has been mixed with data being sent to visitors of completely different websites.

This issue was reported to Cloudflare last Saturday by a Google researcher. They have been working frantically since then to fix it.

This data leak was announced several hours ago on the Google Project Zero mailing list and on the Cloudflare blog. Some of the leaked data has been indexed by search engines who have been working to scrub the data from their caches.

To help explain the issue and help you secure your website, we have published details of what occurred and how to secure your website in case you have been affected by this data leak.

You can find the full post on our blog....

Regards,



Mark Maunder
Wordfence Founder & CEO

More info:
https://www.wordfence.com/blog/2017/02/cloudflare-data-leak/
https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/
 

zappaDPJ

Moderator
Joined
Aug 26, 2010
Messages
8,450
Wow! I wonder what 0.00003% of HTTP requests equates to in real money. I suspect it's a whole lot more than that figure suggests.
 

pierce

Habitué
Joined
Apr 10, 2016
Messages
1,165
cloudflare said:
Your domain is not one of the domains where we have discovered exposed data in any third party caches. The bug has been patched so it is no longer leaking data. However, we continue to work with these caches to review their records and help them purge any exposed data we find. If we discover any data leaked about your domains during this search, we will reach out to you directly and provide you full details of what we have found.

150 domains affected out of hundreds of thousands?
 
Top