AIRLINK 79.41 Increased By ▲ 1.02 (1.3%)
BOP 5.33 Decreased By ▼ -0.01 (-0.19%)
CNERGY 4.38 Increased By ▲ 0.05 (1.15%)
DFML 33.19 Increased By ▲ 2.32 (7.52%)
DGKC 76.87 Decreased By ▼ -1.64 (-2.09%)
FCCL 20.53 Decreased By ▼ -0.05 (-0.24%)
FFBL 31.40 Decreased By ▼ -0.90 (-2.79%)
FFL 9.85 Decreased By ▼ -0.37 (-3.62%)
GGL 10.25 Decreased By ▼ -0.04 (-0.39%)
HBL 117.93 Decreased By ▼ -0.57 (-0.48%)
HUBC 134.10 Decreased By ▼ -1.00 (-0.74%)
HUMNL 7.00 Increased By ▲ 0.13 (1.89%)
KEL 4.67 Increased By ▲ 0.50 (11.99%)
KOSM 4.74 Increased By ▲ 0.01 (0.21%)
MLCF 37.44 Decreased By ▼ -1.23 (-3.18%)
OGDC 136.70 Increased By ▲ 1.85 (1.37%)
PAEL 23.15 Decreased By ▼ -0.25 (-1.07%)
PIAA 26.55 Decreased By ▼ -0.09 (-0.34%)
PIBTL 7.00 Decreased By ▼ -0.02 (-0.28%)
PPL 113.75 Increased By ▲ 0.30 (0.26%)
PRL 27.52 Decreased By ▼ -0.21 (-0.76%)
PTC 14.75 Increased By ▲ 0.15 (1.03%)
SEARL 57.20 Increased By ▲ 0.70 (1.24%)
SNGP 67.50 Increased By ▲ 1.20 (1.81%)
SSGC 11.09 Increased By ▲ 0.15 (1.37%)
TELE 9.23 Increased By ▲ 0.08 (0.87%)
TPLP 11.56 Decreased By ▼ -0.11 (-0.94%)
TRG 72.10 Increased By ▲ 0.67 (0.94%)
UNITY 24.82 Increased By ▲ 0.31 (1.26%)
WTL 1.40 Increased By ▲ 0.07 (5.26%)
BR100 7,526 Increased By 32.9 (0.44%)
BR30 24,650 Increased By 91.4 (0.37%)
KSE100 71,971 Decreased By -80.5 (-0.11%)
KSE30 23,749 Decreased By -58.8 (-0.25%)

imageSAN FRANCISCO: Internet users Friday were being urged to change all their passwords in the wake of a Cloudflare bug that could have leaked passwords, messages and more from website visits.

A Cloudflare service used by millions of websites to enhance security and performance said that it had fixed the flaw quickly after being alerted a week ago by Google researcher Tavis Ormandy.

"It turned out that in some unusual circumstances, our edge servers were running past the end of a buffer and returning memory that contained private information such as HTTP cookies, authentication tokens, HTTP POST bodies, and other sensitive data," Cloudflare chief technology officer John Graham-Cumming said in a blog post.

"And some of that data had been cached by search engines."

Essentially, sensitive data intended to be temporarily stored overflowed "buffering" memory space and was then tucked into more exposed spots such as web pages that could then be captured by online search engines, according to descriptions of the bug.

"We fetched a few live samples and we observed encryption keys, cookies, passwords, chunks of POST data and even HTTPS requests for other major Cloudflare-hosted sites from other users," Ormandy said in an online post about the flaw.

"This situation was unusual, (personally identifiable information) was actively being downloaded by crawlers and users during normal usage, they just didn't understand what they were seeing."

Ormandy said in a Twitter message fired off from @taviso that Cloudflare has been leaking information for months, jeopardizing supposedly secure data at major websites including Uber, OKCupid, Fitbit and 1Password.

A cry for people to change all of their online passwords because of the bug buzzed at Twitter, where "#CloudBleed" hashtag was a trending topic.

Copyright AFP (Agence France-Press), 2017

Comments

Comments are closed.