
The Cloudflare service has existed since 2009 and, as the company’s website says, “forces the Internet to work as it should.” In fact, Cloudfare is an intermediary between the site and the user who simultaneously protects customer servers (that is, one or another site or service) and accelerates the opening of the site for ordinary visitors.
For example, the owners of small services using Cloudflare get rid of the need to spend money on the server and protect against DDOS attacks-the question of access to the sites of their customers Cloudflare takes on and filters requests that are similar to attacks. The service also protects all the data passing through its network and guarantees their confidentiality. Many Cloudflare functions are free and available for owners of small sites, but the company also works with very large customers: Uber, OKCUPID dating site, password storage service and others, including the Russian Avito ads.
Cloudflare is the largest similar service, more than five million different sites use its services. He has repeatedly protected sites from large DDOS attacks.
As the Google Network Security Specialist Tavis Ormandi found out, with a regular appeal to a specific page on the Cloudflare network, the service gave not only the requested data, but also part of the data of some other service. At first it seemed to him that the mistake in his own code (Ormandi worked on some of his project), but then he found out that this is a vulnerability on the side of Cloudflare-this happened when this or that page was made up with errors from the point of view of one of the service mechanisms. Moreover, among the data there was personal data and information about the authorization of users who work with the service. Including Ormandi managed to find information from Uber and Okcupid sites. He destroyed the information received.
This happened about once for three million requests, but if you take into account the number of Cloudflare customers, then vulnerability should be taken extremely seriously. Moreover, if you find a page with errors once through which the data flows, then you can contact it as many times as you like - and each time you receive confidential information from the Cloudflare network.
The error crept into a system that prepares pages for distribution through the Google AMP service, accelerating the viewing of sites on mobile devices. Due to the vulnerability, the accidental amount of data fell into open access and they were indexed by search engines. As it was found in Cloudflare (it took almost a week for a detailed analysis), the vulnerability appeared no later than September 22, 2016 - that is, random portions of confidential data, including personal information of users of the largest companies, fell into open access.
Among the "leaked" information was the encryption key that was used in Cloudflare to protect their own networks.
“It was a mistake in the thing that understands HTML. We recognize changes in the web pages on the fly, and pass through our systems so that it works, pages should be in our memory. It turned out that you can reach the end of the page and get to that part of the memory where it was not worth watching, ” explains one of the creators of Cloudflare John Graham Camming.
It is not known for reliably what kind of data came into open access, and whether anyone could find it. Cloudflare claim that no attackers did not manage to use the vulnerability, because they did not know about her - although it existed for almost six months. The company assures that otherwise it would certainly find a suspicious activity of hackers.
If these statements are true, the first to learn about the vulnerability was the computer security specialist from Google, who did not have any bad motives, then the main problem of leakage is in the data casted by Internet search engines. Cloudflare has already begun active work with all the largest search engines and quickly eliminates all confidential information in front of his eyes (Medusa managed to find non -public data from the Uber service in one of the Cash pages, and after several hours they ceased to be available).
The GITHUB has already been assembled a list of the largest sites that worked with Cloudflare and could be prone to data leakage. The most important of them, the 1password password storage service, has already stated that its users were safe all the time - the company uses more complex protection systems. Not damage to users of the Russian Avito ads website. In the list of sites whose data could still get into open access, in addition to Uber, there is a Medium blog service, The Pirate Bay Torrent Trekter, 4pda.ru website and many others. If you had an account on one of these sites, it is better to change the password.
Pavel Borisov