{"id":40503,"date":"2017-02-27T15:51:14","date_gmt":"2017-02-27T20:51:14","guid":{"rendered":"http:\/\/www.eagleeyenetworks.com\/bug-cybersecurite-cloudflare-cloudbleed\/"},"modified":"2020-07-13T07:59:23","modified_gmt":"2020-07-13T12:59:23","slug":"bug-cybersecurite-cloudflare-cloudbleed","status":"publish","type":"post","link":"https:\/\/www.een.com\/fr\/blog\/bug-cybersecurite-cloudflare-cloudbleed\/","title":{"rendered":"Bug de S\u00e9curit\u00e9 Cloudflare"},"content":{"rendered":"<p>Eagle Eye Networks n\u2019utilise pas Cloudflare \u2013 un service d\u2019am\u00e9lioration de performances pour sites web.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"alignleft wp-image-40024\" src=\"https:\/\/www.een.com\/wp-content\/uploads\/2017\/02\/cloudflare.jpg\" alt=\"\" width=\"309\" height=\"213\" srcset=\"https:\/\/www.een.com\/wp-content\/uploads\/2017\/02\/cloudflare.jpg 7076w, https:\/\/www.een.com\/wp-content\/uploads\/2017\/02\/cloudflare-300x206.jpg 300w, https:\/\/www.een.com\/wp-content\/uploads\/2017\/02\/cloudflare-1024x704.jpg 1024w, https:\/\/www.een.com\/wp-content\/uploads\/2017\/02\/cloudflare-100x69.jpg 100w, https:\/\/www.een.com\/wp-content\/uploads\/2017\/02\/cloudflare-189x130.jpg 189w, https:\/\/www.een.com\/wp-content\/uploads\/2017\/02\/cloudflare-200x138.jpg 200w, https:\/\/www.een.com\/wp-content\/uploads\/2017\/02\/cloudflare-400x275.jpg 400w, https:\/\/www.een.com\/wp-content\/uploads\/2017\/02\/cloudflare-600x413.jpg 600w, https:\/\/www.een.com\/wp-content\/uploads\/2017\/02\/cloudflare-800x550.jpg 800w, https:\/\/www.een.com\/wp-content\/uploads\/2017\/02\/cloudflare-1200x826.jpg 1200w\" sizes=\"(max-width: 309px) 100vw, 309px\" \/><\/p>\n<p>Il y a eu un probl\u00e8me de s\u00e9curit\u00e9 relativement grave qui a \u00e9t\u00e9 d\u00e9tect\u00e9 par Tavis Ormandy chez Project Zero, concernant le service Cloudflare. Il a remarqu\u00e9 que certaines informations priv\u00e9es pouvaient \u00eatre extraites sous certaines conditions pr\u00e9cises. Un probl\u00e8me de s\u00e9curit\u00e9 grave qui a d\u00e9j\u00e0 \u00e9t\u00e9 r\u00e9solu.<\/p>\n<p>Ce qui est particuli\u00e8rement int\u00e9ressant, c\u2019est qu\u2019une fois que cette vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 connue, Cloudflare a \u00e9t\u00e9 en mesure d\u2019y rem\u00e9dier en 7 heures et 47 minutes. C\u2019est un excellent temps de r\u00e9ponse, et est indicatif de la qualit\u00e9 de service qu\u2019on peut attendre d\u2019un service cloud professionnel.<\/p>\n<p>Afin de pouvoir fournir ce genre de service, les entreprises ont besoin d\u2019une \u00e9quipe compl\u00e8te d\u2019ing\u00e9nieurs en interne, une \u00e9quipe d\u2019op\u00e9rations de haut niveau, et une \u00e9quipe de s\u00e9curit\u00e9 compl\u00e8te en interne aussi. Vous n\u2019obtiendrez pas ce genre de temps de r\u00e9ponse lorsque vous sous-traitez ou que vous utilisez un service qui n\u2019a pas de de personnel complet ou assez professionnel. Trop d\u2019op\u00e9rateurs dans l\u2019industrie de la s\u00e9curit\u00e9 mat\u00e9rielle utilisent des mod\u00e8les de sous-traitance d\u00e9pass\u00e9s ou avec trop peu de personnel.<\/p>\n<p>De toute \u00e9vidence, Eagle Eye dispose d\u2019un staff en interne complet de niveau professionnel. Nous travaillons tr\u00e8s dur sur notre cybers\u00e9curit\u00e9.<\/p>\n<p><a href=\"https:\/\/arstechnica.com\/security\/2017\/02\/serious-cloudflare-bug-exposed-a-potpourri-of-secret-customer-data\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/arstechnica.com\/security\/2017\/02\/serious-cloudflare-bug-exposed-a-potpourri-of-secret-customer-data\/<\/a><br \/>\n<a href=\"https:\/\/blog.cloudflare.com\/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/blog.cloudflare.com\/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Eagle Eye Networks n\u2019utilise pas Cloudflare \u2013 un service d\u2019am\u00e9lioration de performances pour sites web. Il y a eu un probl\u00e8me de s\u00e9curit\u00e9 relativement grave qui a \u00e9t\u00e9 d\u00e9tect\u00e9 par &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.een.com\/fr\/blog\/bug-cybersecurite-cloudflare-cloudbleed\/\"> <span class=\"screen-reader-text\">Bug de S\u00e9curit\u00e9 Cloudflare<\/span> Lire la suite\u00a0\u00bb<\/a><\/p>\n","protected":false},"author":544,"featured_media":40026,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"","_relevanssi_noindex_reason":"","footnotes":""},"categories":[436],"tags":[],"class_list":["post-40503","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-securite-de-cyber"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.een.com\/fr\/wp-json\/wp\/v2\/posts\/40503","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.een.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.een.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.een.com\/fr\/wp-json\/wp\/v2\/users\/544"}],"replies":[{"embeddable":true,"href":"https:\/\/www.een.com\/fr\/wp-json\/wp\/v2\/comments?post=40503"}],"version-history":[{"count":0,"href":"https:\/\/www.een.com\/fr\/wp-json\/wp\/v2\/posts\/40503\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.een.com\/fr\/wp-json\/wp\/v2\/media\/40026"}],"wp:attachment":[{"href":"https:\/\/www.een.com\/fr\/wp-json\/wp\/v2\/media?parent=40503"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.een.com\/fr\/wp-json\/wp\/v2\/categories?post=40503"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.een.com\/fr\/wp-json\/wp\/v2\/tags?post=40503"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}