Graalians

Graalians (https://www.graalians.com/forums/index.php)
-   General Graal Discussion (https://www.graalians.com/forums/forumdisplay.php?f=2)
-   -   Cloudlfare notice (https://www.graalians.com/forums/showthread.php?t=38354)

doomsday 02-24-2017 01:44 PM

cloudflare notice
 
There has been a major security flaw within Cloudflare. It's highly suggested that you cycle your passwords for all affected sites and programs due to this.

Impact
Between 2016-09-22 - 2017-02-18 passwords, private messages, API keys, and other sensitive data were leaked by Cloudflare to random requesters.
Data was cached by search engines , there are private logins for dozens of multiple websites in google's cache right now, and may have been collected by random scrapers over the past few months.

According to CloudFlare: "The greatest period of impact was from February 13 and February 18 with around 1 in every 3,300,000 HTTP requests through Cloudflare potentially resulting in memory leakage (that’s about 0.00003% of requests)". This has a potential of 100k-200k paged with private data leaked every day for the dates in question.

What you should do?
Change all your passwords, especially those on these affected sites. Rotate API keys & secrets, and confirm you have 2-Factor Authentication set up for important accounts. You can set up 2-Factor Authentication for Discord under Settings -> Security.

Sites compronised include: Reddit, Discord, Uber, StackOverflow, Patreon, Yelp, OKCupid, 4chan, Namecheap, DigitalOcean, and many, many more.

You can check which sites were affected by this on the readme of this github page https://github.com/pirate/sites-using-cloudflare

Link to the official discord post: https://blog.discordapp.com/safety-jim-p....z9wga7s8s
Link to the official cloudflare post: https://blog.cloudflare.com/incident-rep...arser-bug/

tricklebean 02-24-2017 01:56 PM

ok thx

Dos 02-24-2017 02:10 PM

and you put it here?

Basi 02-24-2017 09:18 PM

good info
bad spot


All times are GMT. The time now is 10:00 PM.

Powered by vBulletin/Copyright ©2000 - 2026, vBulletin Solutions Inc.