Major security flaw within Cloudflare menu

User Tag List

Results 1 to 5 of 5
  1. #1
    Scumstation's Avatar Super Moderator ♰♰♰♰♰♰♰♰♰♰♰♰♰♰♰
    CoreCoins Purchaser Authenticator enabled
    Reputation
    413
    Join Date
    Jun 2012
    Posts
    601
    Thanks G/R
    82/165
    Trade Feedback
    13 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Major security flaw within Cloudflare

    There has been a major security flaw within Cloudflare and thus meaning within Discord. Its highly suggested that you cycle your passwords everywhere.

    Impact

    Between 2016-09-22 - 2017-02-18 passwords, private messages, API keys, and other sensitive data were leaked by Cloudflare to random requesters.
    Data was cached by search engines, and may have been collected by random adversaries over the past few months.

    "The greatest period of impact was from February 13 and February 18 with around 1 in every 3,300,000 HTTP requests through Cloudflare potentially resulting in memory leakage (that’s about 0.00003% of requests), potential of 100k-200k paged with private data leaked every day"

    What you should do

    Change all your passwords, especially those on these affected sites. Rotate API keys & secrets, and confirm you have 2-FA set up for important accounts. Of the sites compromised, most notably there is Reddit, Uber, StackOverflow, Patreon, DigitalOcean, 4chan, Wago and many many more.

    You can check which sites were affected by this on the readme of this github page GitHub - pirate/sites-using-cloudflare: List of domains using Cloudflare DNS (potentially affected by the CloudBleed HTTPS traffic leak)

    I cannot stress this enough, please change your passwords everywhere as this affects everyone everywhere!

    You can check to see if your email has been leaked by visiting the following website

    Have I been pwned? Check if your email has been compromised in a data breach

    Major security flaw within Cloudflare
  2. Thanks Ket (1 members gave Thanks to Scumstation for this useful post)
  3. #2
    ev0's Avatar ★ Elder ★ murlocs.com

    CoreCoins Purchaser Authenticator enabled
    Reputation
    1850
    Join Date
    Jul 2012
    Posts
    2,737
    Thanks G/R
    313/377
    Trade Feedback
    16 (100%)
    Mentioned
    7 Post(s)
    Tagged
    7 Thread(s)
    Heh, thanks for this. I was wondering why this happen:




    I updated my info immediately, but holy shit that's scary.
    Need a guild in the US? Visit murlocs.com

  4. #3
    CreativeXtent's Avatar Moderator Authenticator enabled
    Reputation
    580
    Join Date
    Jun 2011
    Posts
    1,594
    Thanks G/R
    242/148
    Trade Feedback
    3 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    damn, well. good thing i use a toss away pass on discord.
    "the true wow experience is Maclone"

  5. #4
    Ket's Avatar Legendary
    CoreCoins Purchaser Authenticator enabled
    Reputation
    861
    Join Date
    Feb 2008
    Posts
    3,337
    Thanks G/R
    600/313
    Trade Feedback
    29 (93%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    We have been told that we are not effected but we are following and looking into this issue.

  6. Thanks shahinpb (1 members gave Thanks to Ket for this useful post)
  7. #5
    Teh Canadian's Avatar Elite User CoreCoins Purchaser
    Reputation
    409
    Join Date
    Jul 2012
    Posts
    290
    Thanks G/R
    12/8
    Trade Feedback
    2 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    This security flaw is still amazing me 12 hours later. Countless platforms I know have had some problems including some personal clients.

Similar Threads

  1. [Selling] HardCore Accounts! *Fast!* *Secure!* *Delivery Within 10 Mins!*
    By MagnusGade in forum World of Warcraft Buy Sell Trade
    Replies: 0
    Last Post: 05-01-2015, 12:46 PM
  2. Replies: 17
    Last Post: 03-30-2011, 10:12 AM
  3. WTB ALL "Secure" Accounts! Good prices! (definition for secure within)
    By Palumir in forum Members Only Accounts And CD Keys Buy Sell
    Replies: 13
    Last Post: 09-08-2008, 05:32 PM
  4. Anti-Security Project
    By =sinister= in forum World of Warcraft General
    Replies: 6
    Last Post: 07-09-2006, 10:40 AM
All times are GMT -5. The time now is 10:29 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search