Pages: [1]
Dr Who Fan
BAM!ID: 1075
Joined: 2006-05-31
Posts: 974
Credits: 158,187,435
World-rank: 8,525

2017-02-27 06:03:51

Not sure if or how this will affect BoincStats.com since Willy uses them to keep this site clean from ddos's and other bad things.

Incident report on memory leak caused by Cloudflare parser bug
Last Friday, Tavis Ormandy from Google’s Project Zero contacted Cloudflare to report a security problem with our edge servers. He was seeing corrupted web pages being returned by some HTTP requests run through Cloudflare.

It turned out that in some unusual circumstances, which I’ll detail below, our edge servers were running past the end of a buffer and returning memory that contained private information such as HTTP cookies, authentication tokens, HTTP POST bodies, and other sensitive data. And some of that data had been cached by search engines.

---snip ---

The bug was serious because the leaked memory could contain private information and because it had been cached by search engines. We have also not discovered any evidence of malicious exploits of the bug or other reports of its existence.

The greatest period of impact was from February 13 and February 18 with around 1 in every 3,300,000 HTTP requests through Cloudflare potentially resulting in memory leakage (that’s about 0.00003% of requests).

[BOINCstats] Willy
 
Forum moderator - Administrator - Developer - Tester - Translator
BAM!ID: 1
Joined: 2006-01-09
Posts: 9455
Credits: 353,172,950
World-rank: 4,961

2017-02-27 09:13:21

I have received an email from Cloudflare that BOINCstats was not affected. At my work we also use Cloudflare and there we received no such email (that is however a site only serving images).
Please do not PM, IM or email me for support (they will go unread/ignored). Use the forum for support.
Dr Who Fan
BAM!ID: 1075
Joined: 2006-05-31
Posts: 974
Credits: 158,187,435
World-rank: 8,525

2017-02-27 16:48:26

Willy, Thank you for the fast response and good news!
Dr Who Fan
BAM!ID: 1075
Joined: 2006-05-31
Posts: 974
Credits: 158,187,435
World-rank: 8,525

2017-02-27 16:48:27

Willy, Thank you for the fast response and good news!
Pages: [1]

Index :: BOINCstats general :: Incident report on memory leak caused by Cloudflare parser bug
Reason: