Live data from Hacker News

Hacking Github with Webkit

homakov.blogspot.com

1–10 of 82 posts

Re: Hacking Github with Webkit

#2
"I reported the fixation issue privately only because I'm a good guy and was in a good mood."

I for one am glad that Homakov decided to share and write about these security issues rather than just selling it to the highest bidder. I have learned quite a bit over the past year. And it's deplorable that Github isn't paying anything.

Re: Hacking Github with Webkit

#3
post #2

"I reported the fixation issue privately only because I'm a good guy and was in a good mood." I for one am glad that Homakov decided to share and write about these security issues rather than just selling it to the highest bidder. I have learned quite a bit over the past year. And it's deplorable that Github isn't paying anything.

He was referring to companies which offer bounties (facebook, google etc) and not sites where you can sell your exploits

Re: Hacking Github with Webkit

#4
post #2

"I reported the fixation issue privately only because I'm a good guy and was in a good mood." I for one am glad that Homakov decided to share and write about these security issues rather than just selling it to the highest bidder. I have learned quite a bit over the past year. And it's deplorable that Github isn't paying anything.

He was referring to companies which offer bounties (facebook, google etc) and not sites where you can sell your exploits

yeah. i don't sell exploits yet. Facebook, stripe, shopify, skrill - they treat a reporter nicely.

Re: Hacking Github with Webkit

#5
Wow Homakov, other great write up! I'm really interested in what resources you used to learn all this stuff! Would you mind doing a "recommended books and blogs" post anytime soon?

Re: Hacking Github with Webkit

#6
post #5

Wow Homakov, other great write up! I'm really interested in what resources you used to learn all this stuff! Would you mind doing a "recommended books and blogs" post anytime soon?

honestly, i didn't read a single book about web sec. I just learn things one by one and if something looks weird i investigate. This is why sometimes i publish "known" stuff.

Re: Hacking Github with Webkit

#7
post #4

Earlier quoted context omitted.

He was referring to companies which offer bounties (facebook, google etc) and not sites where you can sell your exploits

yeah. i don't sell exploits yet. Facebook, stripe, shopify, skrill - they treat a reporter nicely.

Any reason why you would even consider selling exploits? Do you not get compensated well from other ventures?

Re: Hacking Github with Webkit

#8
post #5

Wow Homakov, other great write up! I'm really interested in what resources you used to learn all this stuff! Would you mind doing a "recommended books and blogs" post anytime soon?

You can sign up for Cryptography courses at Coursera.org. You learn about basic tenets of crypto like attacker games, cryptogaphic advantage, cracking some exploits (AES-CBC). If you do the problem sets and programming assignments and pass the course without help, you are off to a very good start I would say.

Re: Hacking Github with Webkit

#9
Oops, looks like my tweet (the "open-source GitHub") got a bit more famous than I thought. I feel I must write a big disclaimer here:

I was just joking and would never actually exploit someone that would do so much damage. I was merely commenting on the irony of leaking GitHub on GitHub. Don't fucking do this. It's not fun.

Post reply on HN