Live data from Hacker News

How I hacked Github again

homakov.blogspot.com

91–100 of 202 posts

Re: How I hacked Github again

#92
post #78
post #36

Earlier quoted context omitted.

If you think $400/hr is great, you should see the rate for black-hatting :P

Although you probably should factor in the possibility of several years of compulsory $0.30/hr labour, plus forfeiture of all your ill-gotten gains (and probably some healthily-gotten ones too, they're not so fussy) And that's before legal costs and possible restitution.

Not a concern if you live in Russia or Eastern Europe.

Re: How I hacked Github again

#95

Seeing stuff like this, I want to get into comp-sec. It always sounded interesting, and it looks like it pays well...

Anyone know some good beginner reading material for someone interested in learning this kinda stuff?

I recommend grabbing a copy of Web Application Hackers Handbook[0] and try hacking vulnerable vm's[1].

I see that your a sysadmin so if network hacking is more you speed I would download Metasploit[2] and start hacking old linux or windows distros.

[0]http://www.amazon.com/The-Web-Application-Hackers-Handbook/d... [1]http://itsecgames.blogspot.com/2013/07/bee-box-hack-and-defa... [2] http://www.metasploit.com/

Re: How I hacked Github again

#96
post #82

Earlier quoted context omitted.

Donate or don't donate, that's your call. But why are you complaining about him asking for a donation? Why try to "shame" him? What is he doing to harm you?

Start-up idea: let Hacker News users pay to berate you for x minutes. There's a clearly huge market.

plus.inyourfacetwit.com, where you have 140 chars to berate anyone, and a whaling-wall for when you really need to get it off your chest.

Ad supported. Abusive ads berating potential users are encouraged.

Re: How I hacked Github again

#97

How can I start learning about how to identify exploits like this? I know some basics about web application security and work as a software engineer on a day-to-day basis but security has always been a passion of mine and I have always wanted to be able to support myself through working on security alone (by collecting rewards through bounty programs, self-employed security consulting, working at a security consultin…

[deleted]

Re: How I hacked Github again

#98

How can I start learning about how to identify exploits like this? I know some basics about web application security and work as a software engineer on a day-to-day basis but security has always been a passion of mine and I have always wanted to be able to support myself through working on security alone (by collecting rewards through bounty programs, self-employed security consulting, working at a security consultin…

See my comment below for Web App hacking, my personal favorite, but if you enjoy working in the lower level and reading assembly then the matasano ctf is very well made.

Re: How I hacked Github again

#100
post #86

Earlier quoted context omitted.

If you're talking about for company projects, the enterprise version of Github is self-hosted (e.g. on a VPN): https://enterprise.github.com/

People shouldn't trust the cloud for important source storage. Always self-host anything you want to keep private.

I'm pretty sure many more codebases have been lost through failures to secure internal networks by corporate IT departments than through vulnerabilities in cloud hosting providers.
Post reply on HN