Return-Path: Delivered-To: mail@dorianvasco.de Received: from localhost (localhost [127.0.0.1]) by v22014122474822114.stilfilm.com (Postfix) with ESMTP id 1F8E6D2A76 for ; Fri, 24 Feb 2017 13:20:23 +0100 (CET) X-Virus-Scanned: Debian amavisd-new at v22014122474822114.yourvserver.net X-Spam-Flag: YES X-Spam-Score: 2.688 X-Spam-Level: ** X-Spam-Status: Yes, score=2.688 required=2 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham Received: from v22014122474822114.stilfilm.com ([127.0.0.1]) by localhost (v22014122474822114.yourvserver.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id K_g8SjlsX8cq for ; Fri, 24 Feb 2017 13:20:21 +0100 (CET) Received: from mail26.atl11.rsgsv.net (mail26.atl11.rsgsv.net [205.201.133.26]) by v22014122474822114.stilfilm.com (Postfix) with ESMTP id DCA64D2A5C for ; Fri, 24 Feb 2017 13:20:20 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=k1; d=cloudflare.com; h=Subject:From:Reply-To:To:Date:Message-ID:List-ID:List-Unsubscribe:Content-Type:MIME-Version; i=mprince@cloudflare.com; bh=oJmA/h8T4R9PSKIp6Eg26aKKyIQ=; b=xGShey7iaHJkZ/rjkh6bXwOP6H7CwprNNRi6vfjyj4Ro1ybcLPIS/A08T90LPo7iCBVNx3SS7lir iRRO7I/tNoBJCLwS2/CD4SVCE5RJuyrBaQB/24gJy9iX7dA7YtrKy+yLFmojwp1iUIqraOQ6oSGT I5FtNNMN9UcXxlT7+5w= Received: from (127.0.0.1) by mail26.atl11.rsgsv.net id hm0iga1lgi0p for ; Fri, 24 Feb 2017 12:20:14 +0000 (envelope-from ) Subject: ***SPAM*** =?utf-8?Q?Cloudflare=20parser=20bug=20and=20its=20impact?= From: =?utf-8?Q?Matthew=20Prince?= Reply-To: =?utf-8?Q?Matthew=20Prince?= To: Date: Fri, 24 Feb 2017 12:20:14 +0000 Message-ID: X-Mailer: MailChimp Mailer - **CID3f4b385346d339a9adda** X-Campaign: mailchimpd80d4d74266c0c044b0bcd7ca.3f4b385346 X-campaignid: mailchimpd80d4d74266c0c044b0bcd7ca.3f4b385346 X-Report-Abuse: Please report abuse for this campaign here: http://www.mailchimp.com/abuse/abuse.phtml?u=d80d4d74266c0c044b0bcd7ca&id=3f4b385346&e=d339a9adda X-MC-User: d80d4d74266c0c044b0bcd7ca X-Feedback-ID: 10559331:10559331.586133:us5:mc List-ID: d80d4d74266c0c044b0bcd7camc list X-Accounttype: pr List-Unsubscribe: , x-mcda: FALSE Content-Type: multipart/alternative; boundary="_----------=_MCPart_1931500701" MIME-Version: 1.0 This is a multi-part message in MIME format --_----------=_MCPart_1931500701 Content-Type: text/plain; charset="utf-8"; format="fixed" Content-Transfer-Encoding: quoted-printable Dear Cloudflare Customer: Thursday afternoon=2C we published a blog post describing a memory leak ca= used by a serious bug that impacted Cloudflare's systems. If you haven't y= et=2C I encourage you to read that post on the bug: https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloud= flare-parser-bug/ While we resolved the bug within hours of it being reported to us=2C there= was an ongoing risk that some of our customers' sensitive information cou= ld still be available through third party caches=2C such as the Google sea= rch cache. Over the last week=2C we've worked with these caches to discover what cust= omers may have had sensitive information exposed and ensure that the cache= s are purged. We waited to disclose the bug publicly until after these cac= hes could be cleared in order to mitigate the ability of malicious individ= uals to exploit any exposed data. In our review of these third party caches=2C we discovered data that had b= een exposed from approximately 150 of Cloudflare's customers across our Fr= ee=2C Pro=2C Business=2C and Enterprise plans. We have reached out to thes= e customers directly to provide them with a copy of the data that was expo= sed=2C help them understand its impact=2C and help them mitigate that impa= ct. Fortunately=2C your domain is not one of the domains where we have discove= red exposed data in any third party caches. The bug has been patched so it= is no longer leaking data. However=2C we continue to work with these cach= es to review their records and help them purge any exposed data we find. I= f we discover any data leaked about your domains during this search=2C we= will reach out to you directly and provide you full details of what we ha= ve found. To date=2C we have yet to find any instance of the bug being exploited=2C= but we recommend if you are concerned that you invalidate and reissue any= persistent secrets=2C such as long lived session identifiers=2C tokens or= keys. Due to the nature of the bug=2C customer SSL keys were not exposed= and do not need to be rotated. Again=2C if we discover new information that impacts you=2C we will reach= out to you directly. In the meantime=2C if you have any questions or conc= erns=2C please don=E2=80=99t hesitate to reach out. Matthew Prince Cloudflare=2C Inc. Co-founder and CEO Copyright =C2=A9 2017 Cloudflare=2C All rights reserved. You are receiving this email because you are a Cloudflare customer. Our mailing address is: Cloudflare 101 Townsend Street San Francisco=2C CA 94107 USA Want to change how you receive these emails? You can update your preferences (http://cloudflare.us5.list-manage.com/pro= file?u=3Dd80d4d74266c0c044b0bcd7ca&id=3D14e6d3c1e6&e=3Dd339a9adda) or unsubs= cribe from this list (http://cloudflare.us5.list-manage1.com/unsubscribe?u= =3Dd80d4d74266c0c044b0bcd7ca&id=3D14e6d3c1e6&e=3Dd339a9adda&c=3D3f4b385346) =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --_----------=_MCPart_1931500701 Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable =09 =09=09 =09=09 =09=09 =09=09Cloudflare parser bug and its impact
=09=09=09=09=09=09
=09 =09=09=09 =09=09=09=09
Dear Cloudfla= re Customer:

Thursday afternoon=2C we published a blog post describing a memory leak ca= used by a serious bug that impacted Cloudflare's systems. If you haven't y= et=2C I encourage you to read that post on the bug:

https://blog.cloudflare.com/incident-report-on-memory-leak-caused-= by-cloudflare-parser-bug/

While we resolved the bug within hours of it being reported to us=2C there= was an ongoing risk that some of our customers' sensitive information cou= ld still be available through third party caches=2C such as the Google sea= rch cache.

Over the last week=2C we've worked with these caches to discover what cust= omers may have had sensitive information exposed and ensure that the cache= s are purged. We waited to disclose the bug publicly until after these cac= hes could be cleared in order to mitigate the ability of malicious individ= uals to exploit any exposed data.

In our review of these third party caches=2C we discovered data that had b= een exposed from approximately 150 of Cloudflare's customers across our Fr= ee=2C Pro=2C Business=2C and Enterprise plans. We have reached out to thes= e customers directly to provide them with a copy of the data that was expo= sed=2C help them understand its impact=2C and help them mitigate that impa= ct.

Fortunately=2C your domain is not one of the domains where we have discove= red exposed data in any third party caches. The bug has been patched so it= is no longer leaking data. However=2C we continue to work with these cach= es to review their records and help them purge any exposed data we find. I= f we discover any data leaked about your domains during this search=2C we= will reach out to you directly and provide you full details of what we ha= ve found.

To date=2C we have yet to find any instance of the bug being exploited=2C= but we recommend if you are concerned that you invalidate and reissue any= persistent secrets=2C such as long lived session identifiers=2C tokens or= keys. Due to the nature of the bug=2C customer SSL keys were not exposed= and do not need to be rotated.

Again=2C if we discover new information that impacts you=2C we will reach= out to you directly. In the meantime=2C if you have any questions or conc= erns=2C please don=E2=80=99t hesitate to reach out.

Matthew Prince
Cloudflare=2C Inc.
Co-founder and CEO


 
=09=09=09=09 =09=09=09=09
=09 =09=09=09 =09=09=09=09

Copyright =C2=A9 2017 Cloudflare=2C All rights reserved.

You are receiving this email because you are a Cloudflare customer.

Our mailing address is:
Cloudflare
101 Townsend Street
San Francisco=2C CA 94107

Add us to your address book


Want to change how you receive these emails?
You can update you= r preferences or unsubscribe from this list

=09=09=09=09 =09=09=09=09
=09=09=09=09=09=09
--_----------=_MCPart_1931500701--