2ちゃんねる ■掲示板に戻る■ 全部 1- 最新50    

■ このスレッドは過去ログ倉庫に格納されています

2chも利用しているCloudFlareに脆弱性、個人情報(パスワードなど)が流出の恐れ 浪人終わったな [444574176]

1 :番組の途中ですがアフィサイトへの\(^o^)/です (ワッチョイW 45a8-gkrZ):2017/02/26(日) 12:54:17.92 ID:rXj0au160?2BP(1500)

Last Friday, Tavis Ormandy from Google’s Project Zero contacted Cloudflare to report a security problem with our edge servers.
He was seeing corrupted web pages being returned by some HTTP requests run through Cloudflare.

It turned out that in some unusual circumstances, which I’ll detail below, our edge servers were running past the end of a buffer and returning memory that contained private information
such as HTTP cookies, authentication tokens, HTTP POST bodies, and other sensitive data. And some of that data had been cached by search engines.

For the avoidance of doubt, Cloudflare customer SSL private keys were not leaked.
Cloudflare has always terminated SSL connections through an isolated instance of NGINX that was not affected by this bug.

We quickly identified the problem and turned off three minor Cloudflare features (email obfuscation, Server-side Excludes and Automatic HTTPS Rewrites)
that were all using the same HTML parser chain that was causing the leakage.
At that point it was no longer possible for memory to be returned in an HTTP response.


総レス数 9
3 KB

掲示板に戻る 全部 前100 次100 最新50
read.cgi ver.24052200