Discuz! Board

 找回密码
 立即注册
搜索
热搜: 活动 交友 discuz
查看: 6|回复: 0
打印 上一主题 下一主题

Memory Wave: I Reclaimed My Mental Edge

[复制链接]

51

主题

0

好友

193

积分

注册会员

Rank: 2

跳转到指定楼层
楼主
发表于 11 小时前 |只看该作者 |倒序浏览
Final Friday, Tavis Ormandy from Google_s Venture Zero contacted Cloudflare to report a safety downside with our edge servers. He was seeing corrupted internet pages being returned by some HTTP requests run through Cloudflare. It turned out that in some unusual circumstances, which I_ll detail below, our edge servers have been operating past the top of a buffer and returning Memory Wave that contained non-public info corresponding to HTTP cookies, authentication tokens, HTTP Publish bodies, and other delicate information. And a few of that data had been cached by search engines like google. For the avoidance of doubt, Cloudflare customer SSL private keys were not leaked. Cloudflare has all the time terminated SSL connections by means of an isolated occasion of NGINX that was not affected by this bug. We rapidly recognized the issue and turned off three minor Cloudflare features (email obfuscation, Server-side Excludes and Automatic HTTPS Rewrites) that were all using the same HTML parser chain that was causing the leakage. At that point it was no longer potential for memory to be returned in an HTTP response.
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

Archiver|手机版|Comsenz Inc.

GMT+8, 2025-12-27 21:59 , Processed in 1.146522 second(s), 20 queries .

Powered by Discuz! X2.5

© 2001-2012 Comsenz Inc.

回顶部