ISC StormCast for Monday, February 27th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 27 February 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, February 27th, 2017 edition of the Sandcent Storm Center's Stormcast. My name is Johannes Ulrich, |
| 0:10.4 | and I'm recording from Jacksonville, Florida. Google and Cloudflare announced an interesting vulnerability |
| 0:17.4 | in Cloudflare's infrastructure. Now, if you're not familiar with Cloudflare, |
| 0:23.0 | Cloudflare offers proxy services for large numbers of websites, anything from small hobby |
| 0:30.2 | websites for which Cloudflare offers free services to real massive websites that use Cloudflare for load balancing. |
| 0:40.3 | The problem discovered by Google was that Cloudflare occasionally includes random memory content |
| 0:47.3 | in pages that it serves back to users. The memory content is not at all related to the page that's being served. |
| 0:57.5 | So it could be from a different domain, a different user, and similar to a heart bleed. |
| 1:03.2 | It could include passwords, session cookies, and secret SSL keys. |
| 1:10.4 | So the nature of the vulnerability does appear to be somewhat similar |
| 1:14.6 | to Heart Pleat, but it's limited to Cloudflare. It's not affecting any websites that are not |
| 1:21.8 | hosted behind Cloudflare's proxies. Now, the vulnerability is not at all related to SSL. There are three specific features that Cloudflare's proxies. Now, the vulnerability is not at all related to SSL. There are three |
| 1:30.2 | specific features that Cloudflare points out that caused the leak in conjunction with |
| 1:36.6 | unbalanced HTML tags. Email off-usecation server site excludes and automatic HEPES rewrites did cause the problem. |
| 1:48.7 | For these features, Cloudflare does actually parse the HTML on this site, and then of course |
| 1:55.5 | that's where the leak happened if some HTML tag wasn't closed correctly. |
| 2:01.6 | So what does it really mean to you? |
| 2:03.6 | Well, if you are hosting a website that's behind Cloudflare's proxies, then there is a chance |
| 2:08.6 | that your user's data was leaked as part of this event. |
| 2:13.6 | You should probably notify your users, check with Cloudflare, |
| 2:18.5 | if they have any more guidance there. |
| 2:21.5 | There's also a chance that webpages with leaked data got cached by Google, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

