Live data from Hacker News

How I hacked Github again

homakov.blogspot.com

31–40 of 202 posts

Re: How I hacked Github again

#32

Seeing stuff like this, I want to get into comp-sec. It always sounded interesting, and it looks like it pays well...

Remember that you only see the interesting stories and successful investigations. Before making such a decision you should try to arrange a chat with someone already doing comp-sec, and figure out how much time they spend on all the other stuff.

Re: How I hacked Github again

#33
post #29
post #24

"P.S.2 Love donating? Help Egor on coinbase or paypal: homakov@gmail.com" Maybe it's just me, but asking for donations after saying you bill clients at $400/hr seems weird to me. I wish I could bill at that rate.

There's a number of people who would like donate but not interested in consulting.. There were always people complaining "Add a donate address" Now "why you added a donate address". Oh, Internet.

At least in my experience, I donate to groups that do good work but aren't getting paid for it. I wouldn't donate to people who are being paid (quite handsomely, in this case) for their labor. Especially when he's already clarified that GitHub paid him more than he thought his time was worth.

Re: How I hacked Github again

#34
post #28
post #24

"P.S.2 Love donating? Help Egor on coinbase or paypal: homakov@gmail.com" Maybe it's just me, but asking for donations after saying you bill clients at $400/hr seems weird to me. I wish I could bill at that rate.

Not everyone's time is equal. If you're finding security holes like Egor then an hour of your time is absolutely worth $400/hr.

I totally believe that he's worth that amount of money. I'm sorry if you thought I was questioning that. I'm questioning the juxtaposition of his hourly rate with a request for donations.

Re: How I hacked Github again

#36
post #24

"P.S.2 Love donating? Help Egor on coinbase or paypal: homakov@gmail.com" Maybe it's just me, but asking for donations after saying you bill clients at $400/hr seems weird to me. I wish I could bill at that rate.

If you think $400/hr is great, you should see the rate for black-hatting :P

Re: How I hacked Github again

#37
post #33
post #29

Earlier quoted context omitted.

There's a number of people who would like donate but not interested in consulting.. There were always people complaining "Add a donate address" Now "why you added a donate address". Oh, Internet.

At least in my experience, I donate to groups that do good work but aren't getting paid for it. I wouldn't donate to people who are being paid (quite handsomely, in this case) for their labor. Especially when he's already clarified that GitHub paid him more than he thought his time was worth.

95% of my security research is not paid. I fix gems, libraries, websites etc. Donated money go right there, through beers and coffee I need.

Re: How I hacked Github again

#38
How can I start learning about how to identify exploits like this? I know some basics about web application security and work as a software engineer on a day-to-day basis but security has always been a passion of mine and I have always wanted to be able to support myself through working on security alone (by collecting rewards through bounty programs, self-employed security consulting, working at a security consulting firm like Matasano, or some combination thereof) but I don't know where to start. I want to learn the ins and outs of web application security instead of just understanding the OWASP top 10 and having a strong interest in certain topics (like HTTPS/SSL vulnerabilities). When I read disclosures from people like Egor I grasp the steps they are taking to craft an exploit like this as they are explained but I don't know how to identify these exploits on my own.

Can anyone recommend some reading material or some first steps I can take to work towards moving to a more security-focus career?

Thanks.

Re: How I hacked Github again

#39
post #20
post #4

> $4000 reward is OK. $4000 !? Wow, I'd love to be able to make $4000 on the side just doing what I love. > Interestingly, it would be even cheaper for them to buy like 4-5 hours of my consulting services at $400/hr = $1600. This sounds like a pretty clever strategy for marketing yourself as an effective security consultant. EDIT: $4000!? wow. so money. such big.

Repeatedly and publicly demonstrating how good you are is probably a good way to market yourself in any field.

I will certainly have to try it. Although by doing this with programming, it's probably not as easy to get to the top of HN.

Re: How I hacked Github again

#40
post #33
post #29

Earlier quoted context omitted.

There's a number of people who would like donate but not interested in consulting.. There were always people complaining "Add a donate address" Now "why you added a donate address". Oh, Internet.

At least in my experience, I donate to groups that do good work but aren't getting paid for it. I wouldn't donate to people who are being paid (quite handsomely, in this case) for their labor. Especially when he's already clarified that GitHub paid him more than he thought his time was worth.

Some people actively try to think of money as a proxy for appreciation ;)
Post reply on HN