Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
LinYutang
Oct 12, 2016

NEOLIBERAL SHITPOSTER

:siren:
VOTE BLUE NO MATTER WHO!!!
:siren:
TIL that people will pay Cloudflare to add a bunch of nonsense DIVs in their web pages to deter the evil threat of web scraping

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
Cloudflare's statement: https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/

Westie
May 30, 2013



Baboon Simulator

jre posted:

owns owns owns

Wiggly Wayne DDS
Sep 11, 2010



quote:

We quickly identified the problem and turned off three minor Cloudflare features (email obfuscation, server-side Cusexcludes and Automatic HTTPS Rewrites) that were all using the same HTML parser chain that was causing the leakage.
paging zdr

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

LinYutang posted:

TIL that people will pay Cloudflare to add a bunch of nonsense DIVs in their web pages to deter the evil threat of web scraping

quote:

Many of Cloudflare’s services rely on parsing and modifying HTML pages as they pass through our edge servers. For example, we can insert the Google Analytics tag, safely rewrite http:// links to https://, exclude parts of a page from bad bots, obfuscate email addresses, enable AMP, and more by modifying the HTML of a page.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

jre posted:

Savage

LinYutang
Oct 12, 2016

NEOLIBERAL SHITPOSTER

:siren:
VOTE BLUE NO MATTER WHO!!!
:siren:

Modifying a stream of HTML text: good idea, or great idea?

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
hoowee what a day..

LinYutang
Oct 12, 2016

NEOLIBERAL SHITPOSTER

:siren:
VOTE BLUE NO MATTER WHO!!!
:siren:
Cloudflare has the power to XSS half the internet. Respect.

jre
Sep 2, 2011

To the cloud ?




While claiming a 3 month average is taking the piss a bit, they are correct that the speed with which they fixed this and deployed to massive infra is impressive.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
i'm also kind of impressed that they didn't leak any ssl keys, while simultaneously leaking literally everything else

crazysim
May 23, 2004
I AM SOOOOO GAY
somebody has posted a cloudbleed logo in that report. there's someone who is really deserving of a tshirt right now.

Sapozhnik
Jan 2, 2005

Nap Ghost
:holymoley:

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

crazysim posted:

somebody has posted a cloudbleed logo in that report. there's someone who is really deserving of a wedgie right now.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

jre posted:

Savage

Proteus Jones
Feb 28, 2013




lol

https://bugs.chromium.org/p/project-zero/issues/detail?id=1139

quote:

Cloudflare pointed out their bug bounty program, but I noticed it has a top-tier reward of a t-shirt.


crazysim posted:

somebody has posted a cloudbleed logo in that report. there's someone who is really deserving of a tshirt right now.

Proteus Jones fucked around with this message at 00:50 on Feb 24, 2017

Wiggly Wayne DDS
Sep 11, 2010



itym SHAvage

necrotic
Aug 2, 2005
I owe my brother big time for this!

jre posted:

While claiming a 3 month average is taking the piss a bit, they are correct that the speed with which they fixed this and deployed to massive infra is impressive.

Deployment methodologies for these large scale infrastructure services are really impressive. A global kill switch is one thing but being able to deploy a new build to all their edge nodes as quickly and confidently as they do is awesome.

Last company I worked at only managed 600 or so and working on the deployment infrastructure was some of the most illuminating work I did.

Next job has more like 5 servers total. I don't even know how to work on clusters that small anymore!

pseudorandom name
May 6, 2007

quick, make a bleedflare logo to compete with cloudbleed

jre
Sep 2, 2011

To the cloud ?




gently caress, outdone :magical:

Thanks Ants
May 21, 2004

#essereFerrari



:vince:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

:stare:

Angela Merkle Tree
Jan 4, 2012

the definition of open: "mkdir android ; cd android ; repo init -u git://android.git.kernel.org/platform/manifest.git ; repo sync ; make"
College Slice
just so i'm understanding this properly, the shatter attack requires the collision to be in the first round/block of the file, correct? i've been trying for about an hour to produce a colliding git commit using the colliding block from the PDF, without luck. `shasum` says the files are identical, but `git hash-object` gives different hashes. would this be due to the git header breaking the privileged first-block part of the attack?

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Angela Merkle Tree posted:

just so i'm understanding this properly, the shatter attack requires the collision to be in the first round/block of the file, correct? i've been trying for about an hour to produce a colliding git commit using the colliding block from the PDF, without luck. `shasum` says the files are identical, but `git hash-object` gives different hashes. would this be due to the git header breaking the privileged first-block part of the attack?

ya

http://alblue.bandlem.com/2011/08/git-tip-of-week-objects.html posted:

Git prefixes the object with "blob ", followed by the length (as a human-readable integer), followed by a NUL character, followed by the contents.

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer

LinYutang posted:

"We've discovered (and purged) cached pages that contain private messages from well-known services, PII from major sites that use cloudflare, and even plaintext API requests from a popular password manager that were sent over https (!!)."

Nice, nice

i wonder if this is how exmarx doxxed tb

spankmeister
Jun 15, 2008






quote:

I'm finding private messages from major dating sites, full messages from a well-known chat service, online password manager data, frames from adult video sites, hotel bookings. We're talking full https requests, client IP addresses, full responses, cookies, passwords, keys, data, everything.


:rrrrriiippppp:

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
people could have seen my posts :ohdear:

spankmeister
Jun 15, 2008






Well, since SA is behind buttflare it might be time to change passwords again.

Number19
May 14, 2003

HOCKEY OWNS
FUCK YEAH


https://twitter.com/jcs/status/834922772606308352

:prepop:

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice

lol

apseudonym
Feb 25, 2011

"Terminating TLS is smart and wont blow up in our face!"


:smug:

Shaggar
Apr 26, 2006

flakeloaf
Feb 26, 2003

Still better than android clock


cloumarf

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

somebody post the cloudflare guy's hey taviso stop playing around with desktop av and come work with us and secure the internet tweet

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

https://twitter.com/NathOnSecurity/status/834796736308793344

dragon enthusiast
Jan 1, 2010
has anyone said cloudfart yet

Midjack
Dec 24, 2007



dragon enthusiast posted:

has anyone said cloudfart yet

buttfart

a witch
Jan 12, 2017

gently caress

Adbot
ADBOT LOVES YOU

ozymandOS
Jun 9, 2004

PCjr sidecar posted:

somebody post the cloudflare guy's hey taviso stop playing around with desktop av and come work with us and secure the internet tweet

well i mean


i guess he wasn't wrong

  • Locked thread