Do this kind of thing on your own domain. I have a list of major sites with currently active phishing pages.[1] This is basically a join of PhishTank and DMOZ. Nobody seems to be upset by that. Google is at the top of the list because of their hosting business. It's not just Google Sites. You can put a web site in a Google Spreadsheet cell, which Google doesn't seem to check as a possible phishing site. If you host f…
Okay, so assume he hosted the list himself and is now DDoS'd. Now what? I'll give you a budget of $100 a year.
GitHub censored my research data
101–110 of 206 posts
Re: GitHub censored my research data
#102Earlier quoted context omitted.
This is completely unacceptable. You're treating this as though the author was publishing a list of vulnerabilities about sites. That's not what the author did. The author published a list of sites that are already infected with malware and thus are dangerous for users to visit. This is a public service and there is zero expectation of "responsible disclosure" to the sites. The only thing that disclosing to the sites…
Couldn't agree more. I'm not sure if GL is trying to protect themselves against something and are making up some excuse to justify it but the reasons given for taken down the list don't hold water. GL would be far better stating the real reason for taking the info down (surely there must be one). So far what they've done is seemingly to protect the merchants reputation and perhaps protect GL from some imagined legal…
Re: GitHub censored my research data
#103Earlier quoted context omitted.
> I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. So the malware should be allowed to continue stealing credit card numbers just because the site owners don't know any better? Is that really a position you wish to defend?
No I don't agree that it should be allowed to continue, but how is naming&shaming people going to fix anything? Nothing is going to come of this, other than maybe some other hackers will see them as weak targets. Do you expect this list to be read on prime time CNN or something? People who want to buy something online aren't going to search through GitLab to check if the site has been hacked (maybe they should though…
Someone will make a browser extension that uses this list to warn users?
Re: GitHub censored my research data
#104Earlier quoted context omitted.
> I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. So the malware should be allowed to continue stealing credit card numbers just because the site owners don't know any better? Is that really a position you wish to defend?
No I don't agree that it should be allowed to continue, but how is naming&shaming people going to fix anything? Nothing is going to come of this, other than maybe some other hackers will see them as weak targets. Do you expect this list to be read on prime time CNN or something? People who want to buy something online aren't going to search through GitLab to check if the site has been hacked (maybe they should though…
So it sounds like does a pretty good job of fixing things
[0] https://gwillem.gitlab.io/2016/10/14/github-censored-researc...
Re: GitHub censored my research data
#105Earlier quoted context omitted.
A 'normal consumer' won't be helped by such a technical list on github/gitlab. Do you really believe they would look there? If they wanted protection they could have installed Ad-blockers etc. long time ago already. (Or use more reputable shops)
a lot of non-normal consumers can end up making a lot of noise, sometimes its enough to cause change to happen as was noted, 600 sites have already cleaned up their act > Update Oct 14: 631 stores have been fixed, good work everybody! So is it really as useless as you claim?
The 631 stores have likely been fixed b/c of the publicity (thanks to kicking the list out;)
I think I just don't like when this shame & name business happens on github/gitlab servers. Somewhere else, it's fine.
Re: GitHub censored my research data
#106Earlier quoted context omitted.
Are they in the business of journalism? Lots of people are saying "But the sites are already exploited" ... they are probably still exploitable further also, and GH/GL don't want to be at that party.
Would they be required to publish this story if they "were in the business of journalism"? This is not about whether they are legally required to do anything, but whether what they are doing is responsible behavior.
As for being responsible - that is their motivation.
Should I assume that now you have access to this list that you will be contacting the site owners to notify them their sites are infected & exploitable? Would that be responsible on your part?
Re: GitHub censored my research data
#107We at GitLab believe the author did not responsibly disclose this security information in a proper manner, and today we removed the list of hosts in accordance with our terms of service ( https://about.gitlab.com/terms/ ). The author says that he contacted "about 30 merchants directly", but the published list includes over 1000 merchants. Most merchants were neither informed nor given a chance to respond in a timely…
According to the article, the stores were running malicious javascript which grabs people's credit card info. This obviously means they are vulnerable in some kind of way, but I fail to see how this is reasonably likely to be exploited. Even if it was, you also have to consider the benefit of warning the users. I am not a security expert though, and I might be missing out on something.
The responsibility of GitLab and GitHub is also not to judge if it's "more important" to protect the site owners' businesses or the people going to the sites.
If some sites are running malware, the site owners are responsible for fixing it and not harming the people using their sites, not GitLab or GitHub.
On the contrary if site owners could be harmed by the name of their sites being on such list on GitLab or GitHub, then GitLab or GitHub are responsible according to the DMCA.
So GitLab and GitHub are just acting on what they are held responsible for according to the law.
Disclaimer: I am working as a contractor for GitLab and I am not a lawyer. I took no part in GitLab's decision to censor the list and this is just my own opinion.
Re: GitHub censored my research data
#108GL sent me this statement. For the record, I didn't publish vulnerable systems, I published stores that have malware. --- Willem, GitLab has opted to remove the list of servers that you posted in your snippet. GitLab views the exposure of the vulnerable systems as egregious and will not abide it. While GiLab reserves the right take further action, up to and including termination ( https://about.gitlab.com/terms/ ), w…
Did you ask them for permission to publish a private communication? Probably not, bad of you! - Github/-lab is for projects imho and not a publishing platform. Why don't you publish it on your blog or something? All power to Github/-lab, kick out such stuff!
Re: GitHub censored my research data
#109We at GitLab believe the author did not responsibly disclose this security information in a proper manner, and today we removed the list of hosts in accordance with our terms of service ( https://about.gitlab.com/terms/ ). The author says that he contacted "about 30 merchants directly", but the published list includes over 1000 merchants. Most merchants were neither informed nor given a chance to respond in a timely…
This is completely unacceptable. You're treating this as though the author was publishing a list of vulnerabilities about sites. That's not what the author did. The author published a list of sites that are already infected with malware and thus are dangerous for users to visit. This is a public service and there is zero expectation of "responsible disclosure" to the sites. The only thing that disclosing to the sites…
Re: GitHub censored my research data
#110I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. Most of the owners probably barely know the Googles from the Facebooks, so even if you email them saying 'you have this JavaScript thing that's bad' they won't understand and will blow you off. OP doesn't go into details of how they check the stores, but I'd assume they have some sort of script as they chec…
This had been empirically proven false. As noted in an addendum to the post, 631 broken sites got fixed in just 2 days after the list got published.