Content Injection Attack on GitHub
github.com
Content Injection Attack on GitHub
1–10 of 52 posts
Re: Content Injection Attack on GitHub
#2Re: Content Injection Attack on GitHub
#3Re: Content Injection Attack on GitHub
#4(Injection in LaTeX math tags)
Re: Content Injection Attack on GitHub
#5Re: Content Injection Attack on GitHub
#6The thing I find interesting is that this wasn't a random discovered; like, you look at the first commit in the sequence and you'll see.
> \ce{$\unicode[goombafont; color:red; pointer-events: none; ...
ie. This isn't some random chance discovery.
This is someone looking to use a specific exploit with the ```math tag, already certain that there's some way of doing it.
How strange.
Re: Content Injection Attack on GitHub
#7Re: Content Injection Attack on GitHub
#8You can see in the commit log from on https://github.com/younesbram/younesbram/commit/4282312e4ec3... where the first PoC commit is pushed up. The thing I find interesting is that this wasn't a random discovered; like, you look at the first commit in the sequence and you'll see. > \ce{$\unicode[goombafont; color:red; pointer-events: none; ... ie. This isn't some random chance discovery. This is someone looking to use…
Re: Content Injection Attack on GitHub
#9You can see in the commit log from on https://github.com/younesbram/younesbram/commit/4282312e4ec3... where the first PoC commit is pushed up. The thing I find interesting is that this wasn't a random discovered; like, you look at the first commit in the sequence and you'll see. > \ce{$\unicode[goombafont; color:red; pointer-events: none; ... ie. This isn't some random chance discovery. This is someone looking to use…
it was found by a bunch of anime-pfps on twitter and went "viral"