NexusFi: Find Your Edge


Home Menu

 





Cloudfare Leak


Discussion in Traders Hideout

Updated
    1. trending_up 2,496 views
    2. thumb_up 4 thanks given
    3. group 1 followers
    1. forum 1 posts
    2. attach_file 0 attachments




 
Search this Thread
  #1 (permalink)
 
tturner86's Avatar
 tturner86 
Portland, Oregon
Market Wizard
 
Experience: Intermediate
Platform: F-16CM-40
Trading: GBU-39
Posts: 6,190 since Sep 2013
Thanks Given: 10,460
Thanks Received: 12,695

A huge memory leak was found in the CDN/DNS giant CloudFare's Parser service. Potential information that could've been stolen includes, but is not limited to Passwords, Private Messages, API Keys, IP Addresses, and more between Sept. 22nd 2016 and Feb. 18th 2017. Information was available to random requesters due to the exploit, some even being cached by Search Engines such as Google, meaning advertising companies and anyone who happened to come across it could've picked it up. An estimated 100,000 to 200,000 paged requests of private data was leaked between Feb 13th to Feb 18th per day.

It is highly recommended that you change passwords on the affected sites, if not all passwords. You should also be using Two-Factor Authentication wherever possible.

Popular Affected Websites
-        app.com
- reddit.com
- 1password.com (response: https://blog.agilebits.com/2017/02/23/three-layers-of-encryption-keeps-you-safe-when-ssltls-fails/)
- authy.com
- digitalocean.com
- patreon.com
- bitpay.com
- stackoverflow.com
- 4chan.org
- yelp.com
- uber.com

and 7,385,121 other potentially affected websites
List: https://github.com/pirate/sites-using-cloudflare

For a more in-depth technical description of this exploit, see the following blog post below:
https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/

The bug report on Project Zero
https://bugs.chromium.org/p/project-zero/issues/detail?id=1139


Visit my NexusFi Trade Journal Started this thread Reply With Quote
Thanked by:

 
Best Threads (Most Thanked)
in the last 7 days on NexusFi
Sober Journey With S&P
24 thanks
2026 Jlab journal
10 thanks
Lady Vols Primer: Trading Volatility Journal
7 thanks
Algo automated / semi-automated trading anyone?
6 thanks
Trying to learn Volume and price action correlation
5 thanks




Last Updated on February 24, 2017


© 2026 NexusFi®, s.a., All Rights Reserved.
Av Ricardo J. Alfaro, Century Tower, Panama City, Panama, Ph: +507 833-9432 (Panama and Intl), +1 888-312-3001 (USA and Canada)
All information is for educational use only and is not investment advice. There is a substantial risk of loss in trading commodity futures, stocks, options and foreign exchange products. Past performance is not indicative of future results.
About Us - Contact Us - Site Rules, Acceptable Use, and Terms and Conditions - Downloads - Top
no new posts