GitHub comments abused to push malware via Microsoft repo URLs
bleepingcomputer.com
bleepingcomputer.com
It seems to work initially, but then 5m later the file gets deleted and the link leads to a dead s3 asset page.
So I believe this is fixed. Though the solutions suggested below are crafty, trying to reproduce myself shows me this has been addressed by the GH team
so it doesn't appear to be fixed. :-|
Back in the day when I worked in this field malware writers regularly used things like Youtube as blob-storage and Instagram comments as C2 server mechanism.
Hiding in plain sight can be very effective.
Instead, if Github uploads used the uploader's Github account in the URL path, scammers would need to resort to other means like punycode to mislead users.
Right, a simple way to make these URLs seem less associated with the project in question would be to host them at www.githubusercontent.com (a domain they use for other user-generated content, IIRC). I guess current setup includes an easy way to auth access to the files: if you have access to the repo that's right there in the URL, you can download the file; if it's a private repo that you don't have access to, you get a 404/403. That might save them from a separate metadata lookup.
This is one of those things that seems obvious now, but I could easily see how this could happen, and that kind of URL structure is something I could see myself devising, thinking it's an elegant way to tie the file to other repo access rules.
But really, it's surprising to me that GH keeps around files even if you cancel or delete the comment. Perhaps nowadays they don't need to care that much about storage costs, but back when they added that feature I imagine they might have been more cost-conscious.
I’m sure this is hard, especially at that scale - then again it seems doable eventually.
> This seems simple to fix - deactivate all links that didn’t become part of a published comment.
Currently, a major convenience for the malware spreader is being able to put malware on the server and get a usable URL back without submitting the comment. Deactivating links for unsubmitted comments that were canceled is orthogonal to identifying malware, and wouldn't make the comment readers more vulnerable than they already are.
If you set it to short (hours) it'll be pretty annoying and confusing for people. If you set it too long (more than a day), scammers will just keep generating new links.
It's not that simple to fix, certainly not with these kind of timeouts. The only solution is to not have a "trusted" URL like that.
I’d say no, which I guarantee will break some legitimate packages that depend on files uploaded in GitHub comments.
I love these one-sentence horror stories.
While they are at it maybe they can expire some old files that aren't referenced...
But either way putting the repo in the URL seems completely unnecessary. If you need to track ownership you can still do that in the backing database.
The auth difficulty may make moving the files to a different domain more difficult, but same domain path shouldn't matter.