Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Auritech
May 27, 2004

Blessed be the tailors
The masks are cut to fit

Blessed be the woodworkers
The crosses and the gallows

Blessed be the forgers of iron
And the spikes and the barbwire

Blessed be the stone cutters
It took a quarry to bury the dreams
https://bugs.chromium.org/p/project-zero/issues/detail?id=1139

quote:

(It took every ounce of strength not to call this issue "cloudbleed")

Corpus distillation is a procedure we use to optimize the fuzzing we do by analyzing publicly available datasets. We've spoken a bit about this publicly in the past, for example:

https://security.googleblog.com/2011/08/fuzzing-at-scale.html
http://taviso.decsystem.org/making_software_dumber.pdf#page=11

On February 17th 2017, I was working on a corpus distillation project, when I encountered some data that didn't match what I had been expecting. It's not unusual to find garbage, corrupt data, mislabeled data or just crazy non-conforming data...but the format of the data this time was confusing enough that I spent some time trying to debug what had gone wrong, wondering if it was a bug in my code. In fact, the data was bizarre enough that some colleagues around the Project Zero office even got intrigued.

It became clear after a while we were looking at chunks of uninitialized memory interspersed with valid data. The program that this uninitialized data was coming from just happened to have the data I wanted in memory at the time. That solved the mystery, but some of the nearby memory had strings and objects that really seemed like they could be from a reverse proxy operated by cloudflare - a major cdn service.

A while later, we figured out how to reproduce the problem. It looked like that if an html page hosted behind cloudflare had a specific combination of unbalanced tags, the proxy would intersperse pages of uninitialized memory into the output (kinda like heartbleed, but cloudflare specific and worse for reasons I'll explain later). My working theory was that this was related to their "ScrapeShield" feature which parses and obfuscates html - but because reverse proxies are shared between customers, it would affect *all* Cloudflare customers.

We fetched a few live samples, and we observed encryption keys, cookies, passwords, chunks of POST data and even HTTPS requests for other major cloudflare-hosted sites from other users. Once we understood what we were seeing and the implications, we immediately stopped and contacted cloudflare security.

This situation was unusual, PII was actively being downloaded by crawlers and users during normal usage, they just didn't understand what they were seeing. Seconds mattered here, emails to support on a friday evening were not going to cut it. I don't have any cloudflare contacts, so reached out for an urgent contact on twitter, and quickly reached the right people.

https://twitter.com/taviso/status/832744397800214528

After I explained the situation, cloudflare quickly reproduced the problem, told me they had convened an incident and had an initial mitigation in place within an hour.

"You definitely got the right people. We have killed the affected services"


This bug is subject to a 90 day disclosure deadline. After 90 days elapse
or a patch has been made broadly available, the bug report will become
visible to the public.

That's an ugly bug! Apparently it affects a vast number of sites, including Something Awful, so if you want to be sure, change your pass. Now.

Adbot
ADBOT LOVES YOU

Drunk & Ugly
Feb 10, 2003

GIMME GIMME GIMME, DON'T ASK WHAT FOR
i changed my password to Butthole37

is that safe enough i try to change holes like once a month but someone keeps sneaking in

Auritech
May 27, 2004

Blessed be the tailors
The masks are cut to fit

Blessed be the woodworkers
The crosses and the gallows

Blessed be the forgers of iron
And the spikes and the barbwire

Blessed be the stone cutters
It took a quarry to bury the dreams
That's quite a backdoor!!!

Sophy Wackles
Dec 17, 2000

> access main security grid
access: PERMISSION DENIED.





That's loving crazy thb lol. I wonder if this guy was this first to figure it out.

Auritech
May 27, 2004

Blessed be the tailors
The masks are cut to fit

Blessed be the woodworkers
The crosses and the gallows

Blessed be the forgers of iron
And the spikes and the barbwire

Blessed be the stone cutters
It took a quarry to bury the dreams
I was alerted to it by Brown Moses retweeting a guy who posted the information on it, and since SA is on CloudFlare I had a hunch it might be affected too.

This is the full list of sites affected, it's a very wide swathe of the web:
https://github.com/pirate/sites-using-cloudflare/blob/master/README.md

yeah I eat ass
Mar 14, 2005

only people who enjoy my posting can replace this avatar
If your tweet is so urgent why wouldn't you send it directly to them instead of hoping they namesearch themselves? Or, I don't know, pick up a phone?

Iron Prince
Aug 28, 2005
Buglord
huhu cloudflare leaking passwords?!?! *picks up phone, dials 1-900-MIX-A-LOT, gets a busy signal*

Indy
Mar 30, 2005

Hey guys, what's up?
I guess being lazy and not changing from the suggested pass paid off this time.

Node
May 20, 2001

KICKED IN THE COOTER
:dings:
Taco Defender
I don't use passwords. Everyone already knows I have absolutely nothing of value or worth, so there isn't any point.

Pimpcasso
Mar 13, 2002

VOLS BITCH

Indy posted:

I guess being lazy and not changing from the suggested pass paid off this time.

Zorodius
Feb 11, 2007

EA GAMES' MASTERPIECE 'MADDEN 2018 G.O.A.T. EDITION' IS A GLORIOUS TRIUMPH OF ART AND TECHNOLOGY. IT BRINGS GAMEDAY RIGHT TO THE PLAYER AND WHOEVER SAYS OTHERWISE CAN, YOU GUESSED IT...
SUCK THE SHIT STRAIGHT OUT OF MY OWN ASSHOLE.

BUY IT.
thanks for the notice. though, to be fair, if someone took over my posts, the quality could only improve.

shut up blegum
Dec 17, 2008


--->Plastic Lawn<---

yeah I eat rear end posted:

If your tweet is so urgent why wouldn't you send it directly to them instead of hoping they namesearch themselves? Or, I don't know, pick up a phone?

Phoning people is so nineties

a misanthrope
Jun 21, 2010

:burgerpug::burgerpug::burgerpug::burgerpug::burgerpug:
Is no passwar porblem!

u buy russian viagra now! clika here

dad gay. so what
Feb 18, 2003

by FactsAreUseless
type sudo passwrd -d lowtax on your SA console if you have purchased root access

Hector Beerlioz
Jun 16, 2010

aw, hec
I'M GAY AND STUPID HAHA

Hector Beerlioz
Jun 16, 2010

aw, hec
Oh no I've been hacked!

gimme the GOD DAMN candy
Jul 1, 2007
poo poo, is that how it works? i guess i was hacked years ago and never noticed.

BirryJoru
Mar 21, 2012

GRAMAGEDDON ISN'T OVER YET. SORRY.-RA TEHUTI :smuggo::smug::smugdon::grin::parrot:
This is just a trick. ZDR got hacked and they want us to change our passwords so the new password can be got through the bug.


Not falling for it.

OMFG FURRY
Jul 10, 2006

[snarky comment]
nerds

Stranger Danger Ranger
Jul 21, 2007
There are lizards coming out of my tv.
i don't care about my sa account or anything else for that matter so i'm not gonna do anything about this or anything else for that matter

Gasbraai
Oct 25, 2010

Lictor my Dictor
I have taken the liberty to generate some secure passwords, feel free to use one of these guys:

password
123456
eyemgay

Please don't write these on post-it notes next to your computer or tell them to randos on the street.

dad gay. so what
Feb 18, 2003

by FactsAreUseless
i havent changed my password since the radium over-reaction 14 years ago

Stranger Danger Ranger
Jul 21, 2007
There are lizards coming out of my tv.

dad gay. so what posted:

i havent changed my password since the radium over-reaction 14 years ago

hell of a time. lotta mutants, but they're just trying to get by now like the rest of us. reckon we should give them a chance maybe

gary oldmans diary
Sep 26, 2005
in response to this event i am performing a tactical not doing anything

Fried Watermelon
Dec 29, 2008


I don't even know my SA password, everytime I need to relog in I just get a randomly generated one. So I never leave.

Thots and Prayers
Jul 13, 2006

A is the for the atrocious abominated acts that YOu committed. A is also for ass-i-nine, eight, seven, and six.

B, b, b - b is for your belligerent, bitchy, bottomless state of affairs, but why?

C is for the cantankerous condition of our character, you have no cut-out.
Grimey Drawer
Time to change everything into "MySecurePasswordVersion2!"!

a shiny rock
Nov 13, 2009

lol if you're such a pussy that you need to use a password for anything

Cthulu Carl
Apr 16, 2006

Parallax Scroll posted:

lol if you're such a pussy that you need to use a password for anything

My mere presence is sufficient credentials to log into the forums.

My aura radiates, and the forums submit.

Joust
Dec 7, 2007

No Ledges.

BirryJoru posted:

This is just a trick. ZDR got hacked and they want us to change our passwords so the new password can be got through the bug.


Not falling for it.

Just got confirmation that BirryJoru was hacked. Nice try hacker.

'Change your passwords' confirmed for least hacking chance.

Joust
Dec 7, 2007

No Ledges.
I've just realised I was wrong and BirryJoru was correct!

Moridin920
Nov 15, 2007

by FactsAreUseless
That only affects Cloudflare sites though right not Google stuff?

my SA pw is different from everything else.

Kuato
Feb 25, 2005

"I CAN'T BELIEVE I ATE THE WHOLE THING"
Buglord
I could see Russians hacking one of my accounts, but all of my alt accounts? Pffft, unlikely! :smuggo:

Hell Yeah
Dec 25, 2012

i'm not changing my password from HillaryClinton69

Flesh Forge
Jan 31, 2011

LET ME TELL YOU ABOUT MY DOG
I'm afraid someone might hijack my account and make better posts :ohdear:

unpleasantly turgid
Jul 6, 2016

u lightweights couldn't even feed my shadow ;*

Lunixnerd posted:

I have taken the liberty to generate some secure passwords, feel free to use one of these guys:

password
123456
eyemgay

Please don't write these on post-it notes next to your computer or tell them to randos on the street.

combine them for extra security

unpleasantly turgid
Jul 6, 2016

u lightweights couldn't even feed my shadow ;*

Hell Yeah posted:

i'm not changing my password from HillaryClinton69

me neither

el B
Jan 30, 2004
holler.
My FuckBookNet.net account is compromised!

Xtra Innings Lovin
Nov 11, 2016

gently caress and I just remembered how to log in this morning now I have to change it again????????

The Management
Jan 2, 2010

sup, bitch?
How do we know mods haven't been hacked and this is all a trick to harvest our new passwords?

Nice try jeffk

Adbot
ADBOT LOVES YOU

Nefarious 2.0
Apr 22, 2008

Offense is overrated anyway.

i read all the words in the op

  • Locked thread