four-years-of-spam-mail/spam/1579344113.M263061P15642.sp...

719 lines
27 KiB
Plaintext

Return-Path: <bounce-mc.us5_10559331.586133-mail=dorianvasco.de@mail26.atl11.rsgsv.net>
Delivered-To: mail@dorianvasco.de
Received: from localhost (localhost [127.0.0.1])
by v22014122474822114.stilfilm.com (Postfix) with ESMTP id 1F8E6D2A76
for <mail@dorianvasco.de>; Fri, 24 Feb 2017 13:20:23 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at v22014122474822114.yourvserver.net
X-Spam-Flag: YES
X-Spam-Score: 2.688
X-Spam-Level: **
X-Spam-Status: Yes, score=2.688 required=2 tests=[BAYES_50=0.8,
DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1,
HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989,
RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001,
SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001]
autolearn=ham
Received: from v22014122474822114.stilfilm.com ([127.0.0.1])
by localhost (v22014122474822114.yourvserver.net [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id K_g8SjlsX8cq for <mail@dorianvasco.de>;
Fri, 24 Feb 2017 13:20:21 +0100 (CET)
Received: from mail26.atl11.rsgsv.net (mail26.atl11.rsgsv.net [205.201.133.26])
by v22014122474822114.stilfilm.com (Postfix) with ESMTP id DCA64D2A5C
for <mail@dorianvasco.de>; Fri, 24 Feb 2017 13:20:20 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=k1; d=cloudflare.com;
h=Subject:From:Reply-To:To:Date:Message-ID:List-ID:List-Unsubscribe:Content-Type:MIME-Version; i=mprince@cloudflare.com;
bh=oJmA/h8T4R9PSKIp6Eg26aKKyIQ=;
b=xGShey7iaHJkZ/rjkh6bXwOP6H7CwprNNRi6vfjyj4Ro1ybcLPIS/A08T90LPo7iCBVNx3SS7lir
iRRO7I/tNoBJCLwS2/CD4SVCE5RJuyrBaQB/24gJy9iX7dA7YtrKy+yLFmojwp1iUIqraOQ6oSGT
I5FtNNMN9UcXxlT7+5w=
Received: from (127.0.0.1) by mail26.atl11.rsgsv.net id hm0iga1lgi0p for <mail@dorianvasco.de>; Fri, 24 Feb 2017 12:20:14 +0000 (envelope-from <bounce-mc.us5_10559331.586133-mail=dorianvasco.de@mail26.atl11.rsgsv.net>)
Subject: ***SPAM*** =?utf-8?Q?Cloudflare=20parser=20bug=20and=20its=20impact?=
From: =?utf-8?Q?Matthew=20Prince?= <mprince@cloudflare.com>
Reply-To: =?utf-8?Q?Matthew=20Prince?= <mprince@cloudflare.com>
To: <mail@dorianvasco.de>
Date: Fri, 24 Feb 2017 12:20:14 +0000
Message-ID: <d80d4d74266c0c044b0bcd7ca.d339a9adda.20170224121949.3f4b385346.29d2eeb6@mail26.atl11.rsgsv.net>
X-Mailer: MailChimp Mailer - **CID3f4b385346d339a9adda**
X-Campaign: mailchimpd80d4d74266c0c044b0bcd7ca.3f4b385346
X-campaignid: mailchimpd80d4d74266c0c044b0bcd7ca.3f4b385346
X-Report-Abuse: Please report abuse for this campaign here: http://www.mailchimp.com/abuse/abuse.phtml?u=d80d4d74266c0c044b0bcd7ca&id=3f4b385346&e=d339a9adda
X-MC-User: d80d4d74266c0c044b0bcd7ca
X-Feedback-ID: 10559331:10559331.586133:us5:mc
List-ID: d80d4d74266c0c044b0bcd7camc list <d80d4d74266c0c044b0bcd7ca.150353.list-id.mcsv.net>
X-Accounttype: pr
List-Unsubscribe: <mailto:unsubscribe-mc.us5_d80d4d74266c0c044b0bcd7ca.3f4b385346-d339a9adda@mailin1.us2.mcsv.net?subject=unsubscribe>, <http://cloudflare.us5.list-manage1.com/unsubscribe?u=d80d4d74266c0c044b0bcd7ca&id=14e6d3c1e6&e=d339a9adda&c=3f4b385346>
x-mcda: FALSE
Content-Type: multipart/alternative; boundary="_----------=_MCPart_1931500701"
MIME-Version: 1.0
This is a multi-part message in MIME format
--_----------=_MCPart_1931500701
Content-Type: text/plain; charset="utf-8"; format="fixed"
Content-Transfer-Encoding: quoted-printable
Dear Cloudflare Customer:
Thursday afternoon=2C we published a blog post describing a memory leak ca=
used by a serious bug that impacted Cloudflare's systems. If you haven't y=
et=2C I encourage you to read that post on the bug:
https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloud=
flare-parser-bug/
While we resolved the bug within hours of it being reported to us=2C there=
was an ongoing risk that some of our customers' sensitive information cou=
ld still be available through third party caches=2C such as the Google sea=
rch cache.
Over the last week=2C we've worked with these caches to discover what cust=
omers may have had sensitive information exposed and ensure that the cache=
s are purged. We waited to disclose the bug publicly until after these cac=
hes could be cleared in order to mitigate the ability of malicious individ=
uals to exploit any exposed data.
In our review of these third party caches=2C we discovered data that had b=
een exposed from approximately 150 of Cloudflare's customers across our Fr=
ee=2C Pro=2C Business=2C and Enterprise plans. We have reached out to thes=
e customers directly to provide them with a copy of the data that was expo=
sed=2C help them understand its impact=2C and help them mitigate that impa=
ct.
Fortunately=2C your domain is not one of the domains where we have discove=
red exposed data in any third party caches. The bug has been patched so it=
is no longer leaking data. However=2C we continue to work with these cach=
es to review their records and help them purge any exposed data we find. I=
f we discover any data leaked about your domains during this search=2C we=
will reach out to you directly and provide you full details of what we ha=
ve found.
To date=2C we have yet to find any instance of the bug being exploited=2C=
but we recommend if you are concerned that you invalidate and reissue any=
persistent secrets=2C such as long lived session identifiers=2C tokens or=
keys. Due to the nature of the bug=2C customer SSL keys were not exposed=
and do not need to be rotated.
Again=2C if we discover new information that impacts you=2C we will reach=
out to you directly. In the meantime=2C if you have any questions or conc=
erns=2C please don=E2=80=99t hesitate to reach out.
Matthew Prince
Cloudflare=2C Inc.
Co-founder and CEO
Copyright =C2=A9 2017 Cloudflare=2C All rights reserved.
You are receiving this email because you are a Cloudflare customer.
Our mailing address is:
Cloudflare
101 Townsend Street
San Francisco=2C CA 94107
USA
Want to change how you receive these emails?
You can update your preferences (http://cloudflare.us5.list-manage.com/pro=
file?u=3Dd80d4d74266c0c044b0bcd7ca&id=3D14e6d3c1e6&e=3Dd339a9adda) or unsubs=
cribe from this list (http://cloudflare.us5.list-manage1.com/unsubscribe?u=
=3Dd80d4d74266c0c044b0bcd7ca&id=3D14e6d3c1e6&e=3Dd339a9adda&c=3D3f4b385346)
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
--_----------=_MCPart_1931500701
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
<!doctype html>
<html xmlns=3D"http://www.w3.org/1999/xhtml" xmlns:v=3D"urn:schemas-micros=
oft-com:vml" xmlns:o=3D"urn:schemas-microsoft-com:office:office">
=09<head>
=09=09<!-- NAME: SIMPLE TEXT -->
=09=09<!--[if gte mso 15]>
<xml>
<o:OfficeDocumentSettings>
<o:AllowPNG/>
<o:PixelsPerInch>96</o:PixelsPerInch>
</o:OfficeDocumentSettings>
</xml>
<![endif]-->
=09=09<meta charset=3D"UTF-8">
<meta http-equiv=3D"X-UA-Compatible" content=3D"IE=3Dedge">
<meta name=3D"viewport" content=3D"width=3Ddevice-width=2C initial=
-scale=3D1">
=09=09<title>Cloudflare parser bug and its impact</title>
<style type=3D"text/css">
=09=09p{
=09=09=09margin:10px 0;
=09=09=09padding:0;
=09=09}
=09=09table{
=09=09=09border-collapse:collapse;
=09=09}
=09=09h1=2Ch2=2Ch3=2Ch4=2Ch5=2Ch6{
=09=09=09display:block;
=09=09=09margin:0;
=09=09=09padding:0;
=09=09}
=09=09img=2Ca img{
=09=09=09border:0;
=09=09=09height:auto;
=09=09=09outline:none;
=09=09=09text-decoration:none;
=09=09}
=09=09body=2C#bodyTable=2C#bodyCell{
=09=09=09height:100%;
=09=09=09margin:0;
=09=09=09padding:0;
=09=09=09width:100%;
=09=09}
=09=09#outlook a{
=09=09=09padding:0;
=09=09}
=09=09img{
=09=09=09-ms-interpolation-mode:bicubic;
=09=09}
=09=09table{
=09=09=09mso-table-lspace:0pt;
=09=09=09mso-table-rspace:0pt;
=09=09}
=09=09.ReadMsgBody{
=09=09=09width:100%;
=09=09}
=09=09.ExternalClass{
=09=09=09width:100%;
=09=09}
=09=09p=2Ca=2Cli=2Ctd=2Cblockquote{
=09=09=09mso-line-height-rule:exactly;
=09=09}
=09=09a[href^=3Dtel]=2Ca[href^=3Dsms]{
=09=09=09color:inherit;
=09=09=09cursor:default;
=09=09=09text-decoration:none;
=09=09}
=09=09p=2Ca=2Cli=2Ctd=2Cbody=2Ctable=2Cblockquote{
=09=09=09-ms-text-size-adjust:100%;
=09=09=09-webkit-text-size-adjust:100%;
=09=09}
=09=09.ExternalClass=2C.ExternalClass p=2C.ExternalClass td=2C.ExternalCla=
ss div=2C.ExternalClass span=2C.ExternalClass font{
=09=09=09line-height:100%;
=09=09}
=09=09a[x-apple-data-detectors]{
=09=09=09color:inherit !important;
=09=09=09text-decoration:none !important;
=09=09=09font-size:inherit !important;
=09=09=09font-family:inherit !important;
=09=09=09font-weight:inherit !important;
=09=09=09line-height:inherit !important;
=09=09}
=09=09#bodyCell{
=09=09=09padding:10px;
=09=09}
=09=09.templateContainer{
=09=09=09max-width:600px !important;
=09=09}
=09=09a.mcnButton{
=09=09=09display:block;
=09=09}
=09=09.mcnImage{
=09=09=09vertical-align:bottom;
=09=09}
=09=09.mcnTextContent{
=09=09=09word-break:break-word;
=09=09}
=09=09.mcnTextContent img{
=09=09=09height:auto !important;
=09=09}
=09=09.mcnDividerBlock{
=09=09=09table-layout:fixed !important;
=09=09}
=09=09body=2C#bodyTable{
=09=09=09background-color:#FFFFFF;
=09=09=09background-image:none;
=09=09=09background-repeat:no-repeat;
=09=09=09background-position:center;
=09=09=09background-size:cover;
=09=09}
=09=09#bodyCell{
=09=09=09border-top:0;
=09=09}
=09=09.templateContainer{
=09=09=09border:0;
=09=09}
=09=09h1{
=09=09=09color:#202020;
=09=09=09font-family:Helvetica;
=09=09=09font-size:26px;
=09=09=09font-style:normal;
=09=09=09font-weight:bold;
=09=09=09line-height:125%;
=09=09=09letter-spacing:normal;
=09=09=09text-align:left;
=09=09}
=09=09h2{
=09=09=09color:#202020;
=09=09=09font-family:Helvetica;
=09=09=09font-size:22px;
=09=09=09font-style:normal;
=09=09=09font-weight:bold;
=09=09=09line-height:125%;
=09=09=09letter-spacing:normal;
=09=09=09text-align:left;
=09=09}
=09=09h3{
=09=09=09color:#202020;
=09=09=09font-family:Helvetica;
=09=09=09font-size:20px;
=09=09=09font-style:normal;
=09=09=09font-weight:bold;
=09=09=09line-height:125%;
=09=09=09letter-spacing:normal;
=09=09=09text-align:left;
=09=09}
=09=09h4{
=09=09=09color:#202020;
=09=09=09font-family:Helvetica;
=09=09=09font-size:18px;
=09=09=09font-style:normal;
=09=09=09font-weight:bold;
=09=09=09line-height:125%;
=09=09=09letter-spacing:normal;
=09=09=09text-align:left;
=09=09}
=09=09#templateHeader{
=09=09=09border-top:0;
=09=09=09border-bottom:0;
=09=09}
=09=09#templateHeader .mcnTextContent=2C#templateHeader .mcnTextContent p{
=09=09=09color:#202020;
=09=09=09font-family:Helvetica;
=09=09=09font-size:16px;
=09=09=09line-height:150%;
=09=09=09text-align:left;
=09=09}
=09=09#templateHeader .mcnTextContent a=2C#templateHeader .mcnTextContent=
p a{
=09=09=09color:#2BAADF;
=09=09=09font-weight:normal;
=09=09=09text-decoration:underline;
=09=09}
=09=09#templateBody{
=09=09=09border-top:0;
=09=09=09border-bottom:0;
=09=09}
=09=09#templateBody .mcnTextContent=2C#templateBody .mcnTextContent p{
=09=09=09color:#202020;
=09=09=09font-family:Helvetica;
=09=09=09font-size:16px;
=09=09=09line-height:150%;
=09=09=09text-align:left;
=09=09}
=09=09#templateBody .mcnTextContent a=2C#templateBody .mcnTextContent p a{
=09=09=09color:#2BAADF;
=09=09=09font-weight:normal;
=09=09=09text-decoration:underline;
=09=09}
=09=09#templateFooter{
=09=09=09border-top:0;
=09=09=09border-bottom:0;
=09=09}
=09=09#templateFooter .mcnTextContent=2C#templateFooter .mcnTextContent p{
=09=09=09color:#202020;
=09=09=09font-family:Helvetica;
=09=09=09font-size:12px;
=09=09=09line-height:150%;
=09=09=09text-align:left;
=09=09}
=09=09#templateFooter .mcnTextContent a=2C#templateFooter .mcnTextContent=
p a{
=09=09=09color:#202020;
=09=09=09font-weight:normal;
=09=09=09text-decoration:underline;
=09=09}
=09@media only screen and (min-width:768px){
=09=09.templateContainer{
=09=09=09width:600px !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09body=2Ctable=2Ctd=2Cp=2Ca=2Cli=2Cblockquote{
=09=09=09-webkit-text-size-adjust:none !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09body{
=09=09=09width:100% !important;
=09=09=09min-width:100% !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09#bodyCell{
=09=09=09padding-top:10px !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09.mcnImage{
=09=09=09width:100% !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09.mcnCartContainer=2C.mcnCaptionTopContent=2C.mcnRecContentContainer=
=2C.mcnCaptionBottomContent=2C.mcnTextContentContainer=2C.mcnBoxedTextCont=
entContainer=2C.mcnImageGroupContentContainer=2C.mcnCaptionLeftTextContent=
Container=2C.mcnCaptionRightTextContentContainer=2C.mcnCaptionLeftImageCon=
tentContainer=2C.mcnCaptionRightImageContentContainer=2C.mcnImageCardLeftT=
extContentContainer=2C.mcnImageCardRightTextContentContainer{
=09=09=09max-width:100% !important;
=09=09=09width:100% !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09.mcnBoxedTextContentContainer{
=09=09=09min-width:100% !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09.mcnImageGroupContent{
=09=09=09padding:9px !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09.mcnCaptionLeftContentOuter .mcnTextContent=2C.mcnCaptionRightConten=
tOuter .mcnTextContent{
=09=09=09padding-top:9px !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09.mcnImageCardTopImageContent=2C.mcnCaptionBlockInner .mcnCaptionTopC=
ontent:last-child .mcnTextContent{
=09=09=09padding-top:18px !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09.mcnImageCardBottomImageContent{
=09=09=09padding-bottom:9px !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09.mcnImageGroupBlockInner{
=09=09=09padding-top:0 !important;
=09=09=09padding-bottom:0 !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09.mcnImageGroupBlockOuter{
=09=09=09padding-top:9px !important;
=09=09=09padding-bottom:9px !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09.mcnTextContent=2C.mcnBoxedTextContentColumn{
=09=09=09padding-right:18px !important;
=09=09=09padding-left:18px !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09.mcnImageCardLeftImageContent=2C.mcnImageCardRightImageContent{
=09=09=09padding-right:18px !important;
=09=09=09padding-bottom:0 !important;
=09=09=09padding-left:18px !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09.mcpreview-image-uploader{
=09=09=09display:none !important;
=09=09=09width:100% !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09h1{
=09=09=09font-size:22px !important;
=09=09=09line-height:125% !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09h2{
=09=09=09font-size:20px !important;
=09=09=09line-height:125% !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09h3{
=09=09=09font-size:18px !important;
=09=09=09line-height:125% !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09h4{
=09=09=09font-size:16px !important;
=09=09=09line-height:150% !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09table.mcnBoxedTextContentContainer td.mcnTextContent=2Ctd.mcnBoxedTe=
xtContentContainer td.mcnTextContent p{
=09=09=09font-size:14px !important;
=09=09=09line-height:150% !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09td#templateHeader td.mcnTextContent=2Ctd#templateHeader td.mcnTextCo=
ntent p{
=09=09=09font-size:16px !important;
=09=09=09line-height:150% !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09td#templateBody td.mcnTextContent=2Ctd#templateBody td.mcnTextConten=
t p{
=09=09=09font-size:16px !important;
=09=09=09line-height:150% !important;
=09=09}
}=09@media only screen and (max-width: 480px){
=09=09td#templateFooter td.mcnTextContent=2Ctd#templateFooter td.mcnTextCo=
ntent p{
=09=09=09font-size:14px !important;
=09=09=09line-height:150% !important;
=09=09}
}</style></head>
<body style=3D"background:#FFFFFF none no-repeat center/cover;height:=
100%;margin: 0;padding: 0;width: 100%;-ms-text-size-adjust: 100%;-webkit-=
text-size-adjust: 100%;background-color: #FFFFFF;background-image: none;ba=
ckground-repeat: no-repeat;background-position: center;background-size: co=
ver;">
<center>
<table align=3D"center" border=3D"0" cellpadding=3D"0" cellspa=
cing=3D"0" height=3D"100%" width=3D"100%" id=3D"bodyTable" style=3D"backgr=
ound:#FFFFFF none no-repeat center/cover;border-collapse: collapse;mso-tab=
le-lspace: 0pt;mso-table-rspace: 0pt;-ms-text-size-adjust: 100%;-webkit-te=
xt-size-adjust: 100%;height: 100%;margin: 0;padding: 0;width: 100%;backgro=
und-color: #FFFFFF;background-image: none;background-repeat: no-repeat;bac=
kground-position: center;background-size: cover;">
<tr>
<td align=3D"left" valign=3D"top" id=3D"bodyCell" styl=
e=3D"mso-line-height-rule: exactly;-ms-text-size-adjust: 100%;-webkit-text=
-size-adjust: 100%;height: 100%;margin: 0;padding: 10px;width: 100%;border=
-top: 0;">
<!-- BEGIN TEMPLATE // -->
=09=09=09=09=09=09<!--[if gte mso 9]>
=09=09=09=09=09=09<table align=3D"center" border=3D"0" cellspacing=3D"0" c=
ellpadding=3D"0" width=3D"600" style=3D"width:600px;">
=09=09=09=09=09=09<tr>
=09=09=09=09=09=09<td align=3D"center" valign=3D"top" width=3D"600" style=
=3D"width:600px;">
=09=09=09=09=09=09<![endif]-->
<table border=3D"0" cellpadding=3D"0" cellspacing=
=3D"0" width=3D"100%" class=3D"templateContainer" style=3D"border-collapse=
: collapse;mso-table-lspace: 0pt;mso-table-rspace: 0pt;-ms-text-size-adjus=
t: 100%;-webkit-text-size-adjust: 100%;border: 0;max-width: 600px !importa=
nt;">
<tr>
<td valign=3D"top" id=3D"templateHeader" s=
tyle=3D"mso-line-height-rule: exactly;-ms-text-size-adjust: 100%;-webkit-t=
ext-size-adjust: 100%;border-top: 0;border-bottom: 0;"><table class=3D"mcn=
TextBlock" style=3D"min-width: 100%;border-collapse: collapse;mso-table-ls=
pace: 0pt;mso-table-rspace: 0pt;-ms-text-size-adjust: 100%;-webkit-text-si=
ze-adjust: 100%;" border=3D"0" width=3D"100%" cellspacing=3D"0" cellpaddin=
g=3D"0">
<tbody class=3D"mcnTextBlockOuter">
<tr>
<td class=3D"mcnTextBlockInner" style=3D"padding-top: 9px;mso-=
line-height-rule: exactly;-ms-text-size-adjust: 100%;-webkit-text-size-adj=
ust: 100%;" valign=3D"top">
=09<!--[if mso]>
=09=09=09=09<table align=3D"left" border=3D"0" cellspacing=3D"0" cellpaddi=
ng=3D"0" width=3D"100%" style=3D"width:100%;">
=09=09=09=09<tr>
=09=09=09=09<![endif]-->
=09=09=09
=09=09=09=09<!--[if mso]>
=09=09=09=09<td valign=3D"top" width=3D"600" style=3D"width:600px;">
=09=09=09=09<![endif]-->
<table style=3D"max-width: 100%;min-width: 100%;border-col=
lapse: collapse;mso-table-lspace: 0pt;mso-table-rspace: 0pt;-ms-text-size-=
adjust: 100%;-webkit-text-size-adjust: 100%;" class=3D"mcnTextContentConta=
iner" border=3D"0" align=3D"left" width=3D"100%" cellspacing=3D"0" cellpad=
ding=3D"0">
<tbody><tr>
<td class=3D"mcnTextContent" style=3D"padding: 0px=
18px 9px;font-size: 12px;mso-line-height-rule: exactly;-ms-text-size-adju=
st: 100%;-webkit-text-size-adjust: 100%;word-break: break-word;color: #202=
020;font-family: Helvetica;line-height: 150%;text-align: left;" valign=3D"=
top">
<span style=3D"font-size:14px"><span style=3D"=
font-family:arial=2Chelvetica neue=2Chelvetica=2Csans-serif">Dear Cloudfla=
re Customer:<br>
<br>
Thursday afternoon=2C we published a blog post describing a memory leak ca=
used by a serious bug that impacted Cloudflare's systems. If you haven't y=
et=2C I encourage you to read that post on the bug:<br>
<br>
<a href=3D"http://cloudflare.us5.list-manage.com/track/click?u=3Dd80d4d742=
66c0c044b0bcd7ca&id=3D3ff7537b84&e=3Dd339a9adda" target=3D"_blank" style=
=3D"mso-line-height-rule: exactly;-ms-text-size-adjust: 100%;-webkit-text-=
size-adjust: 100%;color: #2BAADF;font-weight: normal;text-decoration: unde=
rline;">https://blog.cloudflare.com/incident-report-on-memory-leak-caused-=
by-cloudflare-parser-bug/</a><br>
<br>
While we resolved the bug within hours of it being reported to us=2C there=
was an ongoing risk that some of our customers' sensitive information cou=
ld still be available through third party caches=2C such as the Google sea=
rch cache.<br>
<br>
Over the last week=2C we've worked with these caches to discover what cust=
omers may have had sensitive information exposed and ensure that the cache=
s are purged. We waited to disclose the bug publicly until after these cac=
hes could be cleared in order to mitigate the ability of malicious individ=
uals to exploit any exposed data.<br>
<br>
In our review of these third party caches=2C we discovered data that had b=
een exposed from approximately 150 of Cloudflare's customers across our Fr=
ee=2C Pro=2C Business=2C and Enterprise plans. We have reached out to thes=
e customers directly to provide them with a copy of the data that was expo=
sed=2C help them understand its impact=2C and help them mitigate that impa=
ct.<br>
<br>
Fortunately=2C your domain is not one of the domains where we have discove=
red exposed data in any third party caches. The bug has been patched so it=
is no longer leaking data. However=2C we continue to work with these cach=
es to review their records and help them purge any exposed data we find. I=
f we discover any data leaked about your domains during this search=2C we=
will reach out to you directly and provide you full details of what we ha=
ve found.<br>
<br>
To date=2C we have yet to find any instance of the bug being exploited=2C=
but we recommend if you are concerned that you invalidate and reissue any=
persistent secrets=2C such as long lived session identifiers=2C tokens or=
keys. Due to the nature of the bug=2C customer SSL keys were not exposed=
and do not need to be rotated.<br>
<br>
Again=2C if we discover new information that impacts you=2C we will reach=
out to you directly. In the meantime=2C if you have any questions or conc=
erns=2C please don=E2=80=99t hesitate to reach out.<br>
<br>
Matthew Prince<br>
Cloudflare=2C Inc.<br>
Co-founder and CEO</span></span><br>
<br>
&nbsp;
</td>
</tr>
</tbody></table>
=09=09=09=09<!--[if mso]>
=09=09=09=09</td>
=09=09=09=09<![endif]-->
=09=09=09=09<!--[if mso]>
=09=09=09=09</tr>
=09=09=09=09</table>
=09=09=09=09<![endif]-->
</td>
</tr>
</tbody>
</table></td>
</tr>
<tr>
<td valign=3D"top" id=3D"templateBody" sty=
le=3D"mso-line-height-rule: exactly;-ms-text-size-adjust: 100%;-webkit-tex=
t-size-adjust: 100%;border-top: 0;border-bottom: 0;"><table class=3D"mcnTe=
xtBlock" style=3D"min-width: 100%;border-collapse: collapse;mso-table-lspa=
ce: 0pt;mso-table-rspace: 0pt;-ms-text-size-adjust: 100%;-webkit-text-size=
-adjust: 100%;" border=3D"0" width=3D"100%" cellspacing=3D"0" cellpadding=
=3D"0">
<tbody class=3D"mcnTextBlockOuter">
<tr>
<td class=3D"mcnTextBlockInner" style=3D"padding-top: 9px;mso-=
line-height-rule: exactly;-ms-text-size-adjust: 100%;-webkit-text-size-adj=
ust: 100%;" valign=3D"top">
=09<!--[if mso]>
=09=09=09=09<table align=3D"left" border=3D"0" cellspacing=3D"0" cellpaddi=
ng=3D"0" width=3D"100%" style=3D"width:100%;">
=09=09=09=09<tr>
=09=09=09=09<![endif]-->
=09=09=09
=09=09=09=09<!--[if mso]>
=09=09=09=09<td valign=3D"top" width=3D"600" style=3D"width:600px;">
=09=09=09=09<![endif]-->
<table style=3D"max-width: 100%;min-width: 100%;border-col=
lapse: collapse;mso-table-lspace: 0pt;mso-table-rspace: 0pt;-ms-text-size-=
adjust: 100%;-webkit-text-size-adjust: 100%;" class=3D"mcnTextContentConta=
iner" border=3D"0" align=3D"left" width=3D"100%" cellspacing=3D"0" cellpad=
ding=3D"0">
<tbody><tr>
<td class=3D"mcnTextContent" style=3D"padding: 0px=
18px 9px;font-size: 12px;mso-line-height-rule: exactly;-ms-text-size-adju=
st: 100%;-webkit-text-size-adjust: 100%;word-break: break-word;color: #202=
020;font-family: Helvetica;line-height: 150%;text-align: left;" valign=3D"=
top">
<em><img src=3D"https://gallery.mailchimp.com/=
d80d4d74266c0c044b0bcd7ca/images/85a3dcec-27ef-4ff0-821a-7485b7e3a017.png"=
style=3D"width: 150px;height: 51px;margin: 0px;border: 0;outline: none;te=
xt-decoration: none;-ms-interpolation-mode: bicubic;" align=3D"none" heigh=
t=3D"51" width=3D"150"><br>
Copyright =C2=A9 2017 Cloudflare=2C All rights reserved.</em><br>
You are receiving this email because you are a Cloudflare customer.<br>
<br>
<strong>Our mailing address is:</strong><br>
<div class=3D"vcard"><span class=3D"org fn">Cloudflare</span><div class=3D=
"adr"><div class=3D"street-address">101 Townsend Street</div><span class=
=3D"locality">San Francisco</span>=2C <span class=3D"region">CA</span> <s=
pan class=3D"postal-code">94107</span></div><br><a href=3D"http://cloudfla=
re.us5.list-manage1.com/vcard?u=3Dd80d4d74266c0c044b0bcd7ca&id=3D14e6d3c1e=
6" class=3D"hcard-download">Add us to your address book</a></div>
<br>
<br>
Want to change how you receive these emails?<br>
You can <a href=3D"http://cloudflare.us5.list-manage.com/profile?u=3Dd80d4=
d74266c0c044b0bcd7ca&id=3D14e6d3c1e6&e=3Dd339a9adda" style=3D"mso-line-heigh=
t-rule: exactly;-ms-text-size-adjust: 100%;-webkit-text-size-adjust: 100%;=
color: #2BAADF;font-weight: normal;text-decoration: underline;">update you=
r preferences</a> or <a href=3D"http://cloudflare.us5.list-manage1.com/uns=
ubscribe?u=3Dd80d4d74266c0c044b0bcd7ca&id=3D14e6d3c1e6&e=3Dd339a9adda&c=3D3f=
4b385346" style=3D"mso-line-height-rule: exactly;-ms-text-size-adjust: 100=
%;-webkit-text-size-adjust: 100%;color: #2BAADF;font-weight: normal;text-d=
ecoration: underline;">unsubscribe from this list</a><br>
<br>
</td>
</tr>
</tbody></table>
=09=09=09=09<!--[if mso]>
=09=09=09=09</td>
=09=09=09=09<![endif]-->
=09=09=09=09<!--[if mso]>
=09=09=09=09</tr>
=09=09=09=09</table>
=09=09=09=09<![endif]-->
</td>
</tr>
</tbody>
</table></td>
</tr>
<tr>
<td valign=3D"top" id=3D"templateFooter" s=
tyle=3D"mso-line-height-rule: exactly;-ms-text-size-adjust: 100%;-webkit-t=
ext-size-adjust: 100%;border-top: 0;border-bottom: 0;"></td>
</tr>
</table>
=09=09=09=09=09=09<!--[if gte mso 9]>
=09=09=09=09=09=09</td>
=09=09=09=09=09=09</tr>
=09=09=09=09=09=09</table>
=09=09=09=09=09=09<![endif]-->
<!-- // END TEMPLATE -->
</td>
</tr>
</table>
</center>
<img src=3D"http://cloudflare.us5.list-manage.com/track/open.php?u=3Dd=
80d4d74266c0c044b0bcd7ca&id=3D3f4b385346&e=3Dd339a9adda" height=3D"1" wid=
th=3D"1"></body>
</html>
--_----------=_MCPart_1931500701--