4 ms·
See also: https://github.com/pirate/sites-using-cloudflare https://github.com/pirate/sites-using-cloudflare
by zda 10y ago
See also: https://github.com/pirate/sites-using-cloudflare https://github.com/pirate/sites-using-cloudflare
- dorianm 10y agoYup, I started it because he didn't merge my pull request :D https://github.com/pirate/sites-using-cloudflare/pull/55 https://github.com/pirate/sites-using-cloudflare/pull/55
- Operyl 10y agoThat's beyond flawed because he assumes any site that uses cloudflare's NS is using the proxied services. Which is 100% utterly _wrong_.
- WalterGR 10y agoWhat is the correct way? Honest question... Out of hundreds of passwords I potentially need to reset, I'd like to prioritize.
- verroq 10y agoYou have resolve the DNS and see if it points to one of Cloudflare's reverse proxies.
- toyg 10y agoAnd even then, no guarantee. One could host a static shopwindow site on his own, and use CF for the actual backend of a mobile app under a different domain that nobody knows about. There is no real way to know what has leaked and from whom. The only ones with real info are CF and it's clear from the amount of sites they've missed in their purge-requests that even them don't really know.
- raggi 10y agoPasswords and domain lists aren't a good answer. Explained here: https://gist.github.com/raggi/0d22757fee6eff4bb93a573121506098 https://gist.github.com/raggi/0d22757fee6eff4bb93a5731215060...
- CamelCaseName 10y agoBut he explained this at the very top of the readme? >This list contains all domains that use Cloudflare DNS, not just the Cloudflare proxy (the affected service that leaked data). It's a broad sweeping list that includes everything. Just because a domain is on the list does not mean the site is compromised, and sites may be compromised that do not appear on this list.
- Operyl 10y agoOriginally that wasn't the case, iirc, a bunch of angry people complained to get it added.
- nikcub 10y agoA list of Cloudflare DNS customers is almost completely unrelated to the list of sites affected by this bug. Being a DNS customer doesn't mean you're using CF SSL proxy and using the proxy service doesn't mean you're using DNS