@alex_roqo Workers had nothing to do with the vulnerability. The proxy was setup to allow dynamically targeting non-standard ports. You can also change the port without workers using Origin Rules: https://t.co/7hySazxk4G
Recently, a vulnerability was reported to our bug bounty program, in the way some of our code interprets IPv4 addresses mapped into IPv6 addresses. Read about how Cloudflare addressed this vulnerability and what will prevent similar exploits in the future. https://t.co/J8Y6bUmMyJ
On April 18, 2023, I discovered a critical vulnerability in Cloudflare CASB that enabled me to view sensitive information about other customers' Microsoft and GitHub organizations. The issue was promptly fixed by the Cloudflare team. Here is the write-up: https://t.co/aK5qtC962p
@TimLeland@eastdakota@dok2001@Cloudflare The customer can spend time learning how to manually add DNS records (assuming their hosting provider even supports that) or wait out the 60-day lock imposed by ICANN and transfer to a different registrar. Either way, the customer is left with a sour taste in their mouth. 4/4
Why does Cloudflare Registrar not clearly inform customers that they cannot change name servers? This restriction is hidden away in section 6.1 of the Domain Registration Agreement. It should be mentioned in the UI when you register a domain.
@eastdakota@dok2001@Cloudflare
@TimLeland@eastdakota@dok2001@Cloudflare The problem is that this limitation is not made clear during registration. Almost every other registrar allows you to change name servers, so the customer has no reason to expect Cloudflare won't also let them do that. Now the domain is stuck on Cloudflare Registrar. 3/4
@InnerHack Good question. I was running a traceroute and noticed one of the hops used this IP address format. I looked it up and found they were called IPv4-mapped IPv6 addresses. Then I wondered if it could be used in DNS record and, if yes, how Cloudflare would handle it.
@jgrahamc@Cloudflare As it stands right now, I don't feel particularly safe entering my personal or payment information on a site using Cloudflare, simply because I can't know whether the origin connection is encrypted.
This issue could be alleviated with a simple header:
https://t.co/Xg0HnzpFh2
@jgrahamc@Cloudflare Correct me if I'm wrong, but I don't believe this addresses the huge number of sites on "Flexible" because their origin does not support SSL.
These sites will keep deceiving users who see a padlock in the address bar and assume the connection is securely end-to-end encrypted.
@ArtemR@Hacker0x01 2/2
Low or medium severity bugs can take a couple of weeks to get fixed, but they're always happy to give a status update if you ask for it.
(For context, I am currently #1 on Cloudflare's HackerOne program with 19 resolved reports.)
@ArtemR@Hacker0x01 1/2
Cloudflare usually triages reports on the same or next day no matter the severity. The time to resolution, however, depends on the severity and complexity of the fix.
Same-day fixes for very critical bugs is normal, but it takes a couple of days for slightly less severe bugs.
@Qorne Hi, I've unfortunately run into an account limit which I'm working on getting raised. It should hopefully start working again later today. Sorry for the inconvenience.