Earlier quoted context omitted.
Did we really just make an "In Soviet Russia" joke? That was appropriate? Man, I love this place.
Not getting you. And no not my intent. What he said was funny and I found it funny. Nothing to do with Russia at all.
How I hacked Github again
121–130 of 202 posts
Re: How I hacked Github again
#122Shame on github for making these mistakes in the first place, but kudos to them for doing such a great job of engaging the white hats.
If we're shaming any code with security flaws, no one is free of shame. I'm excited by the bounty program, it's a great way to get things like this identified and responsibly disclosed
Re: How I hacked Github again
#123Re: How I hacked Github again
#124Earlier quoted context omitted.
Although you probably should factor in the possibility of several years of compulsory $0.30/hr labour, plus forfeiture of all your ill-gotten gains (and probably some healthily-gotten ones too, they're not so fussy) And that's before legal costs and possible restitution.
Not a concern if you live in Russia or Eastern Europe.
Re: How I hacked Github again
#125Earlier quoted context omitted.
Really great attitude. I would make this your tagline in some way - "I will find vulnerabilities. If I don't, I will become a vulnerability to my own body and attack myself until I do!"
Did we really just make an "In Soviet Russia" joke? That was appropriate? Man, I love this place.
http://en.wikipedia.org/wiki/Yakov_Smirnoff - referred to as a Russian Reversal
Ok, learned something completely wasn't aware of before.
But, no, no intent to make that kind of joke.
Re: How I hacked Github again
#126Ruby Brogrammer Security Fail yet again. Friends don't let friends code in Fails frameworks.
Re: How I hacked Github again
#127Earlier quoted context omitted.
There's a number of people who would like donate but not interested in consulting.. There were always people complaining "Add a donate address" Now "why you added a donate address". Oh, Internet.
At least in my experience, I donate to groups that do good work but aren't getting paid for it. I wouldn't donate to people who are being paid (quite handsomely, in this case) for their labor. Especially when he's already clarified that GitHub paid him more than he thought his time was worth.
Re: How I hacked Github again
#128Earlier quoted context omitted.
It's worth mentioning that Github has forked Rails and is working off their own private branch of Rails 2.3. Not saying that was relevant to this exploit, mind you. https://github.com/github/rails http://www.kalzumeus.com/2013/06/17/if-your-business-uses-ra...
It is relevant to this: > I . . . decoded _gist_session cookie (which is regular Rails Base64 encoded cookie) In Rails 4 the session cookie is encrypted with a server-side secret, so the end user can't decipher it.
Re: How I hacked Github again
#129I'm the only that thinks that $4000 was very cheap on part of Github? a security hole like this on the wrong hands would have bring severe consequences to github, consequences so big that they would probably pay $1,000,000 USD for it to never happen. So maybe something in the $50-100K would sound more reasonable. Egor is a great hacker with no business sense? On the other hand, the publicity his service gets for this…