Live data from Hacker News

How I hacked Github again

homakov.blogspot.com

71–80 of 202 posts

Re: How I hacked Github again

#71
post #59
post #51

Earlier quoted context omitted.

0. I spent less than an hour last year because there was no proper motivation.

Ah. How did you get the motivation now? How long did it take to find these bugs?

They launched bounty, this was the motivation to check things i always wanted to check. It took me about 4-5 hours, most of that time I was watching TV shows.

Re: How I hacked Github again

#72
post #33
post #29

Earlier quoted context omitted.

There's a number of people who would like donate but not interested in consulting.. There were always people complaining "Add a donate address" Now "why you added a donate address". Oh, Internet.

At least in my experience, I donate to groups that do good work but aren't getting paid for it. I wouldn't donate to people who are being paid (quite handsomely, in this case) for their labor. Especially when he's already clarified that GitHub paid him more than he thought his time was worth.

Donate or don't donate, that's your call. But why are you complaining about him asking for a donation? Why try to "shame" him? What is he doing to harm you?

Re: How I hacked Github again

#75
post #64

Earlier quoted context omitted.

As briefly as possible? Infosec is hard. Most companies have virtually no security policies. Nobody listens. Black hats are ahead in the arms race and anyone who has decent knowledge (doesn't even have to be anywhere near on a level like Homakov or Zalewski) can pull off all sorts of exploits. Even if they don't strike the application itself, they'll get you through infrastructure that your application relies on. Loo…

Good to know, thanks. Any recommendation for a good read on security best practices for a python/django app?

If you aren't yet familiar with OWASP, start there. https://www.owasp.org/index.php/Main_Page

Here is some OWASP material specific to Django.

If you like reading http://blog.mikeleone.com/2011/10/security-django-and-owasp-...

If you like watching http://www.youtube.com/watch?feature=player_embedded&v=sra9x...

Re: How I hacked Github again

#76
post #67

If @homakov is finding security holes without access to Github repositories, imagine what he'd find if you had him code audit for a few days... He's clearly been going about this the proper white-hat way and ensuring holes are patched before open disclosure... what's there to lose? On the flip side, you could go about doing what you're doing under the presumption nobody is maliciously targeting your user base. In thi…

Completely agree, GitHub private repos are a huge target. Even if you use 2FA, after login it's just a cookie that separates the good from the bad. How could GH improve that? Client-side SSL Certs?

If you're talking about for company projects, the enterprise version of Github is self-hosted (e.g. on a VPN): https://enterprise.github.com/

Re: How I hacked Github again

#77
post #33
post #29

Earlier quoted context omitted.

There's a number of people who would like donate but not interested in consulting.. There were always people complaining "Add a donate address" Now "why you added a donate address". Oh, Internet.

At least in my experience, I donate to groups that do good work but aren't getting paid for it. I wouldn't donate to people who are being paid (quite handsomely, in this case) for their labor. Especially when he's already clarified that GitHub paid him more than he thought his time was worth.

He's also providing this blog post. Something he doesn't have to do and has taught me something as I try to improve myself.

Re: How I hacked Github again

#78
post #36
post #24

"P.S.2 Love donating? Help Egor on coinbase or paypal: homakov@gmail.com" Maybe it's just me, but asking for donations after saying you bill clients at $400/hr seems weird to me. I wish I could bill at that rate.

If you think $400/hr is great, you should see the rate for black-hatting :P

Although you probably should factor in the possibility of several years of compulsory $0.30/hr labour, plus forfeiture of all your ill-gotten gains (and probably some healthily-gotten ones too, they're not so fussy)

And that's before legal costs and possible restitution.

Re: How I hacked Github again

#79
post #15

Earlier quoted context omitted.

"nothing" never happened IRL. I either work extra for free trying to find more, and punch myself until I find something.

Really great attitude. I would make this your tagline in some way - "I will find vulnerabilities. If I don't, I will become a vulnerability to my own body and attack myself until I do!"

Did we really just make an "In Soviet Russia" joke? That was appropriate? Man, I love this place.

Re: How I hacked Github again

#80
post #64

Earlier quoted context omitted.

Good to know, thanks. Any recommendation for a good read on security best practices for a python/django app?

If you aren't yet familiar with OWASP, start there. https://www.owasp.org/index.php/Main_Page Here is some OWASP material specific to Django. If you like reading http://blog.mikeleone.com/2011/10/security-django-and-owasp-... If you like watching http://www.youtube.com/watch?feature=player_embedded&v=sra9x...

[deleted]
Post reply on HN