Hacked: commit to rails master on GitHub
github.com
Hacked: commit to rails master on GitHub
1–10 of 240 posts
Re: Hacked: commit to rails master on GitHub
#2Re: Hacked: commit to rails master on GitHub
#3I'm confused. Is this a generic Github vulnerability or is this a vulnerability in tools outside of Github used by Rails? The 'hacker' seems to suggest it's the former ("Github pwned"), which would be pretty serious stuff.
Re: Hacked: commit to rails master on GitHub
#4I'm confused. Is this a generic Github vulnerability or is this a vulnerability in tools outside of Github used by Rails? The 'hacker' seems to suggest it's the former ("Github pwned"), which would be pretty serious stuff.
Re: Hacked: commit to rails master on GitHub
#5"Today I can pull/commit/push in any repository on github. Jack pot."
Re: Hacked: commit to rails master on GitHub
#6I'm confused. Is this a generic Github vulnerability or is this a vulnerability in tools outside of Github used by Rails? The 'hacker' seems to suggest it's the former ("Github pwned"), which would be pretty serious stuff.
Re: Hacked: commit to rails master on GitHub
#7I'm confused. Is this a generic Github vulnerability or is this a vulnerability in tools outside of Github used by Rails? The 'hacker' seems to suggest it's the former ("Github pwned"), which would be pretty serious stuff.
Re: Hacked: commit to rails master on GitHub
#8Re: Hacked: commit to rails master on GitHub
#9I'm confused. Is this a generic Github vulnerability or is this a vulnerability in tools outside of Github used by Rails? The 'hacker' seems to suggest it's the former ("Github pwned"), which would be pretty serious stuff.
The comments on the commit mention he just raised an issue that few people protect the attributes on their models from mass assignment, which… is one way this could happen.
Kind of a dick move, though. Responsible disclosure, doing it on a Sunday morning, etc, etc.
Re: Hacked: commit to rails master on GitHub
#10If this is a GitHub exploit, and I were GitHub, I would be talking to law enforcement. This is not how adults disclose software vulnerabilities.