Breaking GitHub Private Pages for $35k
robertchen.cc
robertchen.cc
This report helped uncover:
- A bug in Openresty where `ngx.redirect` didn't handle unsafe characters [1]. While the fix is now in the latest version of Openresty, a quick patch was to build the URL safely before using it in the redirect.
- You should check for case sensitivity when reading `__Host` prefixed cookies, and verify the values against your expected format. It's possible for both `__HOST-Foo` and `__Host-Foo` cookies to exist, and only the `__Host` prefix requires the `Secure` and `HttpOnly` attributes [2]. In our case we strip all cookies at the edge using Varnish (VCL) to ensure no user-supplied cookies make it to our origin, and now we also ignore any "Secure" cookies that don't appear to have been set by our servers.
[1]: https://github.com/openresty/lua-nginx-module/pull/1654
[2]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Se...
Usually you can just set a "httpOnly" flag to make sure client-side javascript can't mess with the cookie. But if you also sign the cookie, it further enforces this for any client tampering with the cookie manually too. Because only the server knows the secret for creating a new signature, if the client sends back a cookie that is modified in any way (including case sensitivity), it will be discarded. It should prevent the whole class of bugs caused by "unexpected format".
I'm mentioning the cookie signature stuff because it can be added in an almost blackbox way at the web framework level. Whenever you send back something with set-cookie, also set a signature. Whenever receiving a request, check for that signature too. Though I guess it's not a good idea to try to "roll your own" if your web framework doesn't already support this out of the box.
(same disclaimer, I am not a security expert)
Man, you should have seen the european demoscene in the 90s, half of the geniuses had the same main obstacle: homework from school.
Despite what it may seem IT is still in its infancy which means that we work in a field where pure affinity for the subject and raw curiosity-driven brain power (or in some case, dedication to the task), as well as a couple hundred euros worth of hardware, is enough to get into the most complex parts and sometime redefine them.
Access to all the papers and education you need is insanly open on the internet (unlike other fields), as well as trillions of line of code for you to explore. The only two limits are yourself, and time.
Which is not to say that training and experience have no role, but IT as a field is extremly large and for many parts we're still in an early uncharted phase, so discovery is made by explorers and dedicated people[1].
Still, most dev would gain a lot by going through a good algorithmic course.
[1] While talking about dedication, special mention to the linux everywhere guys. I will never not smile at the idea that some of the best IT protections in the world, costing millions upon millions, from the Xbox to HD-DVD to whatever, were brought down because someone wanted to run it on linux.
It's not that I don't understand what you are saying. I was at the top in school and also as a parent I notice how removed education is from... beauty? It's just that economy dictates the rules. Also, teaching is hard.
My explanation is that americans consider ourselves individually to be exceptional, and have trouble recognizing when others are. To the detriment of everyone.
Dragging down the top 5% to the lowest common denominator is not a benefit to society overall. Would you recommend cancelling AP classes?
This is a big subject; none of us are in a position to do anything other than philosophize. But I do think that when your goal is "socialization" you don't need to force everyone to study the same thing. I think it's a moral tragedy that we hold back our brightest students.
I took a couple of them and dropped them as fast as I could. I found the classes mostly just included more homework than was necessary. I thought it’d be more like university and focus more on lecture, notes, and reading. Writing more essays and more projects was a big NOPE for me.
Though from a policy point of view, we don't need to know those answers: different schools should try different answers (including sending all kids to the same class), parents should send their kids to the schools they deem the best overall package.
I can't imagine what it's like for kids now. It must be hellishly difficult trying to find time for themselves. Gen-Z already is aware that they will not fare much better than me, at best. It must be tough being a kid today.
I had plenty of time, and my parents were rather open regarding hobbies/extracurricular activities.
But they soon had "given up" on making me do thigs, caused by me quitting everything that wasn't novel and dismissing their "inputs". My father is also a generalist, and was never keen on getting focused on single skills (he has some mad skills on some fields though, e.g. swimming, and that took quite some time and effort).
And although we were not poor, my father thought that hobbies don't have to be expensive, quite the opposite for kid's hobbies in fact (but we had our fair share of expensive hobbies and gear: snowboarding and bikes and unicycles and sailing and what not).
But most prominently, being a kid of the eighties, and dur to my parents working with "IT-People" in their job, they thought computers were not at all a desirable past time for a kid/teenager (despite my very urgent interest). A waste of time, either toy or nerd-tool. Somewhat what people previously thought of books.
So my biggest interest (programming) was always something I was myself dismissing and even avoiding for a few very important years, and I spent most of my time as a teenager in front of a TV, gaming or partying/meeting with friends outdoors.
I could have spent that time... differently, and I am not blaming anyone, not my parents and not me. I had a good time, but I might have appreciated a little guidance/company.
I just want to say I know why I was not a mad hacker at 17 - small details in paths are waiting everywhere, and there are more exceptions than rules.
I'm not kidding.
It took me until less than a decade ago to revert the brainwashing and pursue my actual passion (computers and programming). I immediately doubled both my income and my joy-on-the-job.
While i was indeed playing games... i also started reverse engineering the games at the age of 14 so i could cheat.
That started around 2006 so it was a bit more acceptable to be all day on your pc but friends/family never really understood until way later in life.
Every success story, intellectual or not, involves passion and time. I'll never comprehend the mindset that completely prevents a kid from experiencing both.
This takes a lot of time too - when you are with them, and then also when you are not, but your brain is still with them anyway.
There were developers in the classic engineering department - creating the product that gets sold. That's an easy one.
There were developers in the customer support department. This group was known as 'sustaining engineering' and developed the tools for the rest of the customer support department to use to diagnose and troubleshoot issues... along with identifying bugs that one customer has in the software (and then creating patch releases for those customers). They had some really interesting problems solved there like "how do you set up a remote debugger to look at a core file that is greater than 2gb in size?"
There were also developers in the IT department. Along with the sysadmins, DBAs, an helpdesk... the "Internal Business Applications" team was the one that maintained the corporate site, or did projects for other departments that didn't have the headcount for a full time developer of their own (sales department and the cornfugraiton tool). Developers also were the ones that did updates to the ERP and CRM systems. The customer support website was maintained as part of this.
So... the point is that IT can certainly encompass software developers. You'll often see this on various job sites - all of the computer technology jobs tend to get categorized under IT unless the company has a technology product of their own (and then separates it by engineering and IT).
We usually call this "IS" (Information Systems). This usually goes hand in hand with IT as IT/IS.
As someone who once got a $500 bug bounty from Facebook in high school, I'll have to say that this is not so surprising. Finding these bugs is 10% knowing about attack vectors (CSRF, XSS etc.) and 90% spending time trying them out in various forms in all the places you can think of. In school (especially if you're already doing well there) you often have lots of spare time and not so many others way of earning money. And with just a few years of experience with programming/computers there are far quicker ways to earn money.
It's still super impressive work by the author of course!! They are extremely talented! I'm not trying to dismiss what they accomplished; just commenting on the strange dynamic of software security research.
Yes there was a lot of garbage too, but that was to be expected. I came away thinking that i hope these kids remain engaged and invested in society lol.
Innocent until and unless proven guilty.
You don't even need to waste time on college because of the information avaliability, especially when you're already this good before even being able to attend.
Well that completely depends on where you live, and the culture there.
You could be a rock-star 10x dev in every sense of the word, but certain places in the world, if you don't have a degree or decades of industry experience, you will almost certainly never even get an interview.
You will need to seek out, and network your way into positions where you can actually impress some human being, and not get stonewalled by resume-screening software.
For every whizkid without a degree that managed to finesse their way into some hot startup or Big N company, there are likely ten that are wasting their talents on some irrelevant dead-end job doing data entry or whatever.
On the otherside those rock star dev will get their stuff broken because of the above.
You undermine your own point by pointing out that this person is a 1%er.
I'm confused because I remember github.io always mentioned in explanations of the public suffix list and as rationale why the list exists. Looking at the list it sure enough is there. What am I missing?
Thus, with `github.io' on the list, everything on `*.github.io' can't share with each other, but everything on `*.a.github.io' _can_. The author is sharing between `private-org.github.io' and `private-page.private-org.github.io', which is allowed because `private-org.github.io' (or the more general `*.github.io') isn't on the list.
I think him mentioning {anything}.github.io not being on the public suffix list is a slightly misunderstanding. While true, it's expected. The same is true for {anything}.com.
7b7f575f public_suffix_list.dat (Simone Carletti 2013-04-23 11:51:10 +0100 11950) github.ioThe github.io rule means foo.github.io cannot share with bar.github.io.
However foo.private-org.github.io can share with bar.private-org.github.io. The *.github.io rule would prevent that.
Great job.
> "the general implementation is heavily inspired by this" Inspired but flawed because they "rolled their own"
https://web.archive.org/web/20210406074552/https://robertche...
Because of a bug related to parsing integers, the behavior you described can happen in the GitHub pages code. However, it is a far cry from "GitHub accepts arbitrary user input and spits it back out into page HTML without verifying it". That's an exceedingly antagonistic way of putting it - and smacks of "I want to make GitHub look dumb by misstating the problem."
Right, that's not verifying the result.
"alert()" is pretty far cry from an "integer"!
How do you even create an "integer" this bad?