Live data from Hacker News

How I hacked Github again

homakov.blogspot.com

11–20 of 202 posts

Re: How I hacked Github again

#11
post #7

Earlier quoted context omitted.

According to his website, the minimum time you can buy services for is 8 hours so I'm not sure what he means here.

8 hours at 400$/hour will still only be 3200$ and he can presumably spend the remaining 4-3 hours doing more security analysis with less overhead, so it might still be cheaper to hire him as a consultant.

Of course, there's probably also a large chance that he finds nothing in those 8 hours

Re: How I hacked Github again

#12
post #4

> $4000 reward is OK. $4000 !? Wow, I'd love to be able to make $4000 on the side just doing what I love. > Interestingly, it would be even cheaper for them to buy like 4-5 hours of my consulting services at $400/hr = $1600. This sounds like a pretty clever strategy for marketing yourself as an effective security consultant. EDIT: $4000!? wow. so money. such big.

I'm pretty sure Egor's first language isn't English, so OK might mean 'meh it's alright' through to 'hey this is great'. I know a few non-native speakers who do similar things.

OK means it's OK but could be better :P

Re: How I hacked Github again

#13
"Btw it was the same bug I found in VK.com"

Is there an easy way to see what vulnerabilities other websites have had and fixed, and to check if your site has them as well?

Re: How I hacked Github again

#14
post #7

Earlier quoted context omitted.

According to his website, the minimum time you can buy services for is 8 hours so I'm not sure what he means here.

8 hours at 400$/hour will still only be 3200$ and he can presumably spend the remaining 4-3 hours doing more security analysis with less overhead, so it might still be cheaper to hire him as a consultant.

Exactly. + if github would really ask me for consulting I'd consider working for free, just for a testimonial.

Re: How I hacked Github again

#15
post #7

Earlier quoted context omitted.

8 hours at 400$/hour will still only be 3200$ and he can presumably spend the remaining 4-3 hours doing more security analysis with less overhead, so it might still be cheaper to hire him as a consultant.

Of course, there's probably also a large chance that he finds nothing in those 8 hours

"nothing" never happened IRL. I either work extra for free trying to find more, and punch myself until I find something.

Re: How I hacked Github again

#16
As soon as I saw the new bounty program the first thought through my head was "Any Github Hacking leaderboard without homakov at tthe top is an inaccurate one". Congrats on your newest discovery!

Re: How I hacked Github again

#19
post #12

Earlier quoted context omitted.

I'm pretty sure Egor's first language isn't English, so OK might mean 'meh it's alright' through to 'hey this is great'. I know a few non-native speakers who do similar things.

OK means it's OK but could be better :P

Straight from the source, thanks Egor. Great blog post as well, your explanations are really easy to follow for a non-security researcher.

Re: How I hacked Github again

#20
post #4

> $4000 reward is OK. $4000 !? Wow, I'd love to be able to make $4000 on the side just doing what I love. > Interestingly, it would be even cheaper for them to buy like 4-5 hours of my consulting services at $400/hr = $1600. This sounds like a pretty clever strategy for marketing yourself as an effective security consultant. EDIT: $4000!? wow. so money. such big.

Repeatedly and publicly demonstrating how good you are is probably a good way to market yourself in any field.
Post reply on HN