What is the difference between allowing users to put custom JS on a subdomain, vs. someone just opening up the developer console and running whatever JS they like? Does JS loaded from the server have different privileges to JS entered at the console?
Hacking Github with Webkit
11–20 of 82 posts
Re: Hacking Github with Webkit
#12Oops, looks like my tweet (the "open-source GitHub") got a bit more famous than I thought. I feel I must write a big disclaimer here: I was just joking and would never actually exploit someone that would do so much damage. I was merely commenting on the irony of leaking GitHub on GitHub. Don't fucking do this. It's not fun.
I didn't clone github/github, steps are theoretical
Re: Hacking Github with Webkit
#13Earlier quoted context omitted.
yeah. i don't sell exploits yet. Facebook, stripe, shopify, skrill - they treat a reporter nicely.
Any reason why you would even consider selling exploits? Do you not get compensated well from other ventures?
Re: Hacking Github with Webkit
#14> Custom JS on your subdomains is a bad idea What is the difference between allowing users to put custom JS on a subdomain, vs. someone just opening up the developer console and running whatever JS they like? Does JS loaded from the server have different privileges to JS entered at the console?
Re: Hacking Github with Webkit
#15> Custom JS on your subdomains is a bad idea What is the difference between allowing users to put custom JS on a subdomain, vs. someone just opening up the developer console and running whatever JS they like? Does JS loaded from the server have different privileges to JS entered at the console?
Re: Hacking Github with Webkit
#16> Custom JS on your subdomains is a bad idea What is the difference between allowing users to put custom JS on a subdomain, vs. someone just opening up the developer console and running whatever JS they like? Does JS loaded from the server have different privileges to JS entered at the console?
Re: Hacking Github with Webkit
#17Earlier quoted context omitted.
yeah. i don't sell exploits yet. Facebook, stripe, shopify, skrill - they treat a reporter nicely.
Any reason why you would even consider selling exploits? Do you not get compensated well from other ventures?
how much would someone pay for this vuln? We can discuss it... homakov@gmail.com
Re: Hacking Github with Webkit
#18Re: Hacking Github with Webkit
#19I am not an expert in security but when I started using github pages a week ago. When I realized I could put any Javascript on the github.com domain I thought: good luck with making this secure.