Serious Change your password.

Joined
Sep 29, 2016
Messages
197
Nebulae
210
In CloudFlare happened major leak of data from client-websites.

In the CloudFlare, world famous company, that provides a variety of services for the maintenance and security of sites, there was a leak of personal data, including cookies, the API, keys and passwords. The company said this two days ago in their blog. While it was not seen cases of deliberate use of these data, but it is necessary to take into consideration, that part of them could be cached by search engines.

How this happened?

The problem was discovered on February 18 Google Project Zero employee Tavis Ormandy, but she could appear September 22, 2016. CloudFlare announced that amount of data leak began to rise since February 13, when a change in the code led to the fact that every 3rd 300 300th HTTP-request became public - and this is serious for a network of this scale.

https://twitter.com/taviso/status/832744397800214528?ref_src=twsrc^tfw

Ormandy said that he found records of hotel reservations, the passwords from the password management, communication with online dating sites. "I do not even know how much of the Internet is in Cloudflare CDN, - he wrote on 19 February. - We are talking about a full HTTP-requests, the IP-address of the client, cookies, passwords, keys, data, everything, "After representatives CloudFlare saw the message Ormandy, they turned off the three features that used the vulnerable code, and contacted with the search engines. to remove cached information.

cloudflarecode.png


And what was leaked?

Leakage (informally named Cloudbleed in honor of the exploit Heartbleed) was the result of "buffer overflow" errors in code generated HTML-parser Ragel, previously used by the company. CloudFlare announced that the bug was present in the system for several years, but was only discovered after moving to a different parser, cf-html, that "changed the buffering process" and led to the leak.

The company explains the delay in the announcement of the leak desire to "make sure that all the search engines will be cleared before the public announcement." It is worth noting that CloudFlare was able to detect all three sources of leaks in just 7 hours after posts by Ormandy and it is really fast - remember the recent history with Microsoft, which did not fix the vulnerability for 90 days, causing Google to publicly report it. However, just in case, should change all passwords, considering how much information is actually stored in CloudFlare.

In the process of writing the news, we have found that an enthusiast wrote extension for Chrome, which checks to see if there are sites of your bookmarkers in «Cloudbleed list." Its source code is also available on GitHub.

Also i want o notice, that if you have similar password on a lot of websites - change all, because they can try to use this data not for only steam or neb.cloud
And, on most of big services, like steam, facebook, gmail e.t.c. exist thing named "Double authentification" or "Mobile authentification", that wouldn't allow villiane to get access to your account.
 
Last edited:

heaveN

bomber rat
Joined
Apr 26, 2016
Messages
1,774
Nebulae
3,706
But you need to go through steam to login on the forum friend
 
Joined
Sep 29, 2016
Messages
197
Nebulae
210
But you need to go through steam to login on the forum friend

The thing, that you don't actually know, how steam login actually works. Does it use only your profile page data, or it contain a password in it. As well, you send cookie with steam data in it to nebulous.cloud every time you connect to forums, so you can't be sure, what part of your data is leaked.

And, after all, change of password is never would be bad thing.
 

Sixx

Proton
Joined
Jul 28, 2016
Messages
220
Nebulae
286
Well you don't need to change your password to be honest. I think all of us use the steam mobile authenticator,
I don't mean to start shit over the internet but is there really any need to post things like this? OP is just trying to warn people just to be safe better than sorry

Why u heff 2 b mad iz only forum ¯\_(ツ)_/¯
 
Reactions: List

Chicken Rickler

Proton
B A N N E D
Joined
Aug 9, 2016
Messages
276
Nebulae
187
Fail: Get your site database leaked
Epic Fail: Be a company that provides technologies to securise websites from attacks, have a drunk cunt change one line of code causing full data from users to be leaked in epic proportions left and right
 
Reactions: List

moonman

Proton
B A N N E D
Joined
May 7, 2016
Messages
374
Nebulae
880
The thing, that you don't actually know, how steam login actually works. Does it use only your profile page data, or it contain a password in it.

??? yes we do ???
http://steamcommunity.com/dev?l=english

Well you don't need to change your password to be honest. I think all of us use the steam mobile authenticator,

in case of steam you're safe but watch out for sites such as google that offer SMS authorization, people have been reported to call up your actual mobile provider and get a duplicate SIM card to get said SMS messages on their own

tl;dr use apps when possible you're probably going to get fucked by some shitty roleplay forum you registered for and forgot anyway so hope for the best

big necro but i felt this was relevant
 
Reactions: List

green name

Proton
Joined
Sep 3, 2016
Messages
129
Nebulae
74
The thing, that you don't actually know, how steam login actually works. Does it use only your profile page data, or it contain a password in it. As well, you send cookie with steam data in it to nebulous.cloud every time you connect to forums, so you can't be sure, what part of your data is leaked.

And, after all, change of password is never would be bad thing.
too lazy
 

Knight

`impulse-approved
B A N N E D
Joined
Sep 17, 2016
Messages
8,135
Nebulae
24,718
This is pretty good to know. Just changed a bunch of my shit.
 
Reactions: List