Jump to content

Cloudflare Reverse Proxies are Dumping Uninitialized Memory

vorticalbox
21 minutes ago, LAwLz said:

Everyone should change their passwords regardless of whether or not the sites you use have 2 factor authentication. Having your password out there is bad.

 

And I will take this opportunity to shill recommend Keepass2.

No need to pay money for a password manager when there is a great one that's free and open source out there.

Paying for a password manager isn't an issue for me, although I too would rather use Keepass2 as well. :)

It's the value of my time and sanity having to go through all my accounts that makes me never want to use any online services again. But alas, that's a liability us consumers must take if we're to use the internet. We can't have it both ways. :( 

Desktop: KiRaShi-Intel-2022 (i5-12600K, RTX2060) Mobile: OnePlus 5T | Koodo - 75GB Data + Data Rollover for $45/month
Laptop: Dell XPS 15 9560 (the real 15" MacBook Pro that Apple didn't make) Tablet: iPad Mini 5 | Lenovo IdeaPad Duet 10.1
Camera: Canon M6 Mark II | Canon Rebel T1i (500D) | Canon SX280 | Panasonic TS20D Music: Spotify Premium (CIRCA '08)

Link to comment
Share on other sites

Link to post
Share on other sites

Amazing, I'm going to have to change all my passwords.

If you want to reply back to me or someone else USE THE QUOTE BUTTON!                                                      
Pascal laptops guide

Link to comment
Share on other sites

Link to post
Share on other sites

I'll take the risk. I don't have time to sift through my logins to figure out which are affected & change them. And I definitely don't have time to change every password.

Link to comment
Share on other sites

Link to post
Share on other sites

36 minutes ago, HarryNyquist said:

I'll take the risk. I don't have time to sift through my logins to figure out which are affected & change them. And I definitely don't have time to change every password.

I added a list and a website that allows you to see if a given site is effected. I would just change password to ones you care about.

                     ¸„»°'´¸„»°'´ Vorticalbox `'°«„¸`'°«„¸
`'°«„¸¸„»°'´¸„»°'´`'°«„¸Scientia Potentia est  ¸„»°'´`'°«„¸`'°«„¸¸„»°'´

Link to comment
Share on other sites

Link to post
Share on other sites

I'm looking at a list of sites affected, and I think LTT might be the only one I actually use. I'll browse some of those other affected sites like Reddit, but I never actually made a log-in for any of them. Sooo... hopefully, I'm okay?

Link to comment
Share on other sites

Link to post
Share on other sites

Im sick and tired of this crap ! changing passwords every week pisses me off !

Connection200mbps / 12mbps 5Ghz wifi

My baby: CPU - i7-4790, MB - Z97-A, RAM - Corsair Veng. LP 16gb, GPU - MSI GTX 1060, PSU - CXM 600, Storage - Evo 840 120gb, MX100 256gb, WD Blue 1TB, Cooler - Hyper Evo 212, Case - Corsair Carbide 200R, Monitor - Benq  XL2430T 144Hz, Mouse - FinalMouse, Keyboard -K70 RGB, OS - Win 10, Audio - DT990 Pro, Phone - iPhone SE

Link to comment
Share on other sites

Link to post
Share on other sites

Damn. The transport for London is there. :o

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitors: 24" Acer S240HLBID + 24" Samsung  | OS: Win 10 Pro

 

Audio: Behringer Q802USB Xenyx 8 Input Mixer |  U-PHORIA UMC204HD | Behringer XM8500 Dynamic Cardioid Vocal Microphone | Sound Blaster Audigy Fx PCI-E card.

 

Home Lab:  Lenovo ThinkCenter M82 ESXi 6.7 | Lenovo M93 Tiny Exchange 2019 | TP-LINK TL-SG1024D 24-Port Gigabit | Cisco ASA 5506 firewall  | Cisco Catalyst 3750 Gigabit Switch | Cisco 2960C-LL | HP MicroServer G8 NAS | Custom built SCCM Server.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just my luck, I think this is the 3rd time I've had to change my passwords in the last 4 months xD 

Link to comment
Share on other sites

Link to post
Share on other sites

So many sites affected. I'm sure I won't be able to remember all the sites I've got accounts on.

The ending is just the beginning repeating.

Link to comment
Share on other sites

Link to post
Share on other sites

Keepass FTW! I had 4 accounts that were affected and just went and changed them to another randomly generated 20-30 character password. Took me longer to update copy the new database to my NAS and phone than it did to actually change the passwords lol.

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, KuJoe said:

Cloudflare has always and will always be a bad idea. When did the internet stop caring about MITM attacks?

When they started believing that HTTPS was enough. MITM attacks aren't the easiest to pull off successfully.

                     ¸„»°'´¸„»°'´ Vorticalbox `'°«„¸`'°«„¸
`'°«„¸¸„»°'´¸„»°'´`'°«„¸Scientia Potentia est  ¸„»°'´`'°«„¸`'°«„¸¸„»°'´

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, vorticalbox said:

When they started believing that HTTPS was enough. MITM attacks aren't the easiest to pull off successfully.

Unless you give the attacker total control of your DNS like people do with Cloudflare.

-KuJoe

Link to comment
Share on other sites

Link to post
Share on other sites

6 hours ago, KuJoe said:

Cloudflare has always and will always be a bad idea. When did the internet stop caring about MITM attacks?

The benefits of using a WAF and CDN like CF far exceed the risk of an event like this. The risk of a MITM attack now is lower than ever before, due to the wide adoption of technology like HTTPS and HSTS. 

Plus, for the majority of websites, handing off to another company which has specialization in security is a much better option than them rolling their own. 

15" MBP TB

AMD 5800X | Gigabyte Aorus Master | EVGA 2060 KO Ultra | Define 7 || Blade Server: Intel 3570k | GD65 | Corsair C70 | 13TB

Link to comment
Share on other sites

Link to post
Share on other sites

16 minutes ago, Blade of Grass said:

The benefits of using a WAF and CDN like CF far exceed the risk of an event like this. The risk of a MITM attack now is lower than ever before, due to the wide adoption of technology like HTTPS and HSTS. 

Plus, for the majority of websites, handing off to another company which has specialization in security is a much better option than them rolling their own. 

I wish more people would understand this concept (ignore the Hearthstone gameplay, he makes an example at 3 minutes in):

 

 

Using a CDN is the right thing to do. Just because it in this situation turned out to backfire doesn't mean it would have been the right thing to not use it.

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, LAwLz said:

I wish more people would understand this concept (ignore the Hearthstone gameplay, he makes an example at 3 minutes in):

 

 

Using a CDN is the right thing to do. Just because it in this situation turned out to backfire doesn't mean it would have been the right thing to not use it.

I guess I'm too much of a nerd to use commercial CDNs when I can roll my own for cheap.

29 minutes ago, Blade of Grass said:

The benefits of using a WAF and CDN like CF far exceed the risk of an event like this. The risk of a MITM attack now is lower than ever before, due to the wide adoption of technology like HTTPS and HSTS. 

Plus, for the majority of websites, handing off to another company which has specialization in security is a much better option than them rolling their own. 

In your opinion yes, but this isn't the first time Cloudflare has messed up and it won't be the last time. I used to use Cloudflare many moons ago for my personal websites where the impact of such a breach was so minimal it didn't matter, but I would never give any company control over my business websites regardless of the risks. That's my personal views on the subject.

-KuJoe

Link to comment
Share on other sites

Link to post
Share on other sites

Found out about this during WAN show. Since the password I use on here is the same for 80% of my login I spent the last hour using LastPass to change all my passwords.

CPU: Intel 5930K - GPU: EVGA Nvidia GTX 980Ti SSCMotherboard: Asus X-99 PRO/USB 3.1 - RAM: 32GB HyperX Savage @ 2800mhz CL14  Case: Phtanteks Eclipse P400 Tempered Glass - Cooling: Corsair H100i V2 / Fractal Design Venturi Fans Storage: PNY XLR8 120 GB SSD (OS) + Seagate 2TB HDD (Games)

Link to comment
Share on other sites

Link to post
Share on other sites

cloudflare data is still in bing caches, this is still a problem

 

http://cc.bingj.com/cache.aspx?q=&d=4857656909960944&w=rj9cgKJZJYOhAbxPoQ4RPcxV_spLZkc2

 

 

                     ¸„»°'´¸„»°'´ Vorticalbox `'°«„¸`'°«„¸
`'°«„¸¸„»°'´¸„»°'´`'°«„¸Scientia Potentia est  ¸„»°'´`'°«„¸`'°«„¸¸„»°'´

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×