MyBB Community Forums

Full Version: Cloudflare's memory leak vulnerability & impact on the Community Forums
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2
As disclosed yesterday, Cloudflare reverse proxies - used by many websites for performance and security purposes including the MyBB Community Forums - have suffered from a memory leak vulnerability. This means that some sensitive information like account credentials and keys that have passed through the CDN's proxy servers may have been compromised by being randomly attached to HTTP responses.

The issue is related to changes to Cloudflare's HTML parser software deployed on September 22, 2016 (the earliest date any memory leak could have occurred) and its increased usage since February 13 (when the issue started affecting the majority of websites using Cloudflare). Google's Project Zero, a security research division focusing on popular products, have contacted Cloudflare on February 18 - at 0424 GMT a temporary fix has been applied globally.
According to Cloudflare, approximately 0.00003% of requests to the CDN's proxy servers included information originating from invalid regions of memory. As some of those have been cached by Google's and other search engines' robots, the companies have been cooperating to remove such entries from their indexes.

Although we have started encrypting connections to *.mybb.com both before and after the CDN inspects the traffic as early as August 2016, we believe the third party servers have been leaking data that was unencrypted at the time of inspection and therefore we advise all Community Forums users to change their passwords as soon as possible.

This vulnerability is related to all sites using the Cloudflare network and their users and administrators should take similar precautions.

Incident report on Cloudflare blog: https://blog.cloudflare.com/incident-rep...arser-bug/
Google's Project Zero issue history: https://bugs.chromium.org/p/project-zero...il?id=1139

The MyBB Team
Is there a plugin that forces members to change their password? My forum uses Cloudflare.
What is the reason CloudFlare is used here? For the DDOS protection?
(2017-02-24, 08:11 PM)nollidnosnhoj Wrote: [ -> ]Is there a plugin that forces members to change their password? My forum uses Cloudflare.
You can issue a SQL command that would remove the password and login key data, forcing users to reset their account via e-mail (access to some accounts may be lost this way): https://community.mybb.com/thread-206694...pid1256320

(2017-02-24, 08:22 PM)spork985 Wrote: [ -> ]What is the reason CloudFlare is used here? For the DDOS protection?
Yes, that's one of the main reasons.
Quote:Is there a plugin that forces members to change their password? My forum uses Cloudflare.
Ive used this one and works
https://github.com/wpillar/mybb-forcepasswordchange
come on...another cloudflare we want !!!
Cloudfare, hmm, looks like things are getting stormy in the clouds.
does this extend beyond mybb boards?
(2017-02-25, 05:25 AM)Butterball Wrote: [ -> ]does this extend beyond mybb boards?

Yes.

https://github.com/pirate/sites-using-cloudflare
(2017-02-25, 06:44 AM)BritishKitten Wrote: [ -> ]
(2017-02-25, 05:25 AM)Butterball Wrote: [ -> ]does this extend beyond mybb boards?

Yes.

https://github.com/pirate/sites-using-cloudflare

does this affect every single mybb forum out there, even those that don't use cloudflare?

I guess, if a site isn't found through the cloudbleed tool: http://cloudflarelistcheck.abal.moe/
no worries
Pages: 1 2