April 2013 Summaries
6 posts from Cloudflare
Filter
Month:
Year:
Post Summaries
Back to Blog
CloudFlare has officially opened its first international office in London near St. Paul's Cathedral. The decision to open an office outside Silicon Valley was driven by the need for high-quality software engineering, network operations and technical support personnel, as well as expanding 24/7 operations and support. London's thriving start-up community also provides access to talented individuals in various fields. The new location allows CloudFlare to extend working hours and achieve round-the-clock operations with just two offices. Additionally, being in London brings the company closer to many of its customers and partners. CloudFlare is currently hiring in both San Francisco and London.
Apr 28, 2013
293 words in the original blog post.
On April 24, 2013, the research firm Sucuri discovered a serious vulnerability in two popular WordPress caching plugins, W3 Total Cache and WP Super Cache. The flaw allows remote PHP code execution on servers running these plugins. CloudFlare has implemented protection against this vulnerability for all its users, including free accounts. However, it is recommended that users of the affected plugins upgrade immediately to secure versions (W3TC 0.9.2.9 and WP Super Cache 1.3.x) or disable them until upgraded. The attack exploits certain functions in these plugins, enabling arbitrary PHP commands to be executed on the server. This could lead to unauthorized access, database manipulation, or malware installation.
Apr 24, 2013
371 words in the original blog post.
CloudFlare logs information about site visits for security and performance reasons. They generate over 20GB of log data per minute, which translates to more than 10 Petabytes annually. Most customer access logs are discarded within 4 hours due to storage limitations. For Enterprise customers, raw log files can be exported and are stored for up to 3 days by default. Aggregate data is generated for analytics purposes, including hit counts, page views, bandwidth usage, and unique visitors. This data also helps identify security threats and implement protection measures across all CloudFlare-secured sites. Error logs are kept for a week before being discarded. In the future, CloudFlare plans to provide more options for customers who want greater insight into site visitor data while maintaining privacy controls.
Apr 23, 2013
592 words in the original blog post.
The text discusses highlights from live video interviews conducted at Parallels Summit in February, featuring industry experts such as CEO of TuCows Elliot Noss, Business Manager at Hostnet Merjin de Brabander, Owner of ViUX JT Smith, Director of Support at Limestone Networks Kris Anderson, and Executive Vice President at Atomia Magnus Hult. Topics covered include mobile services, hosting providers' expansion across the world, and companies' plans for 2013. TuCows' Ting service is highlighted as a competitor to AT&T and Verizon in mobile services, while Hostnet discusses its growing application and POA program. ViUX focuses on improving performance and reliability for customers, emphasizing customer service. Limestone Networks specializes in mission-critical data infrastructure with a focus on superior support. Lastly, Atomia is working to make it easier for businesses to run by automating hosting providers' billing platforms.
Apr 11, 2013
268 words in the original blog post.
On April 11, 2013, a significant brute force attack was launched on numerous WordPress blogs across the internet. The attacker targeted administrative portals using the username "admin" and tried thousands of passwords. A botnet with more than tens of thousands of unique IP addresses was used to execute the attack. There is concern that this attack may be building a larger botnet for future, potentially more damaging attacks. CloudFlare has released a rule through its WAF to detect and stop the signature of the attack, providing protection to all its customers, including those on the free plan.
Apr 11, 2013
332 words in the original blog post.
At Cloudflare, the focus is on eliminating bottlenecks in their network infrastructure. They use port bonding technology to maximize network throughput from servers. In their G3 specification, routers have multiple 10Gbps ports and switches have a handful of 10Gbps ports connected to routers and 48 1Gbps ports connected to servers. Servers have six 1Gbps ports for network connectivity.
To increase utilization, servers can perform any key Cloudflare functions such as DNS, front-line, caching, and logging. This allows them to scale capacity across storage, CPU, and RAM by adding more servers. However, this requires significant communication between servers across the local area network (LAN).
Port bonding is implemented to deal with challenges related to bandwidth and network interrupts during denial of service attacks. They use mode 4, 802.3ad Dynamic Link Aggregation, which requires switches that support it. The Nitty Gritty section provides detailed steps on how to set up port bonding in their custom Linux OS.
In addition, they disable the irqbalance service and explicitly setup IRQ handling to isolate external and internal network traffic. This ensures that customers under attack are isolated from those who are not while still delivering maximum performance by fully utilizing all the gear in their network. The next generation of servers (G4) will jump from 1Gbps network interfaces up to 10Gbps, further increasing throughput and IRQ handling capabilities.
Apr 08, 2013
2,063 words in the original blog post.