Hacking Github with Webkit
homakov.blogspot.com
homakov.blogspot.com
I for one am glad that Homakov decided to share and write about these security issues rather than just selling it to the highest bidder. I have learned quite a bit over the past year. And it's deplorable that Github isn't paying anything.
For example, when you negotiate your annual raise, your best alternative is the raise you could get by moving to another employer (adjusted for benefits, time spent commuting, how fun the job is etc). You don't have to explicitly say to your boss "give me a raise or I'll quit" - your boss just needs to know your options are open.
If homakov publicly says he'd never consider selling an exploit, he's saying his BATNA is $0 and some kudos on Hacker News. If he says he's undecided, his BATNA would be somewhere between a few thousand and a few hundred thousand dollars. Needless to say, the former statement closes off a lot of negotiation options while the latter leaves them open.
[0] http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...
He can likely get compensated much, much better for an original 0day on a big site.
how much would someone pay for this vuln? We can discuss it... homakov@gmail.com
Hey, anyone, is github that super profitable company with 100mln investments ? They got no money or what?
I was just joking and would never actually exploit someone that would do so much damage. I was merely commenting on the irony of leaking GitHub on GitHub. Don't fucking do this. It's not fun.
I didn't clone github/github, steps are theoretical
A few months back didn't your blog do something devious to people who read it? (Oh, yeah! It was signing people out of their Google accounts, I think?) Anyway, now I'm leery of clicking any links to homakov.blogspot.com.... :-p
I do think I'm safe from you, though. I browse with cookies off, NoScript enabled (except for small whitelist), and RequestPolicy blocking cross-site requests. Homakov, can you think of any sort of exploits I'd be vulnerable to when browsing the web?
But the downside is I had to open this page in a different browser to reply to you just now. And things like Gmail, GitHub, etc, I use in my other browser, but I try to keep the sites I use "unprotected" to a minimum.
On the whole, a fair trade-off I think.
About 598,000 results (0.23 seconds)
2) PROFIT
3) MOAR PROFIT
4) EVEN MOAR PROFIT
It's hard to blame them though. Security is easy to miss. Myself and many other people who use github, and who understand those issues, don't really think about it until someone points this out...
[1] http://security.stackexchange.com/q/12412/7306 - just an example of a discussion about this very same issue from about a year ago (and it wasn't new even then)
EDIT: layout
If I would consider it as a new attack I would call it Homakov Cookie Tossing Attack. Now it's just cookie tossing.
It's more of an observation on how even well-known security vulnerabilities can go overlooked. Even by companies with as big exposure and as many resources as github.
What is the difference between allowing users to put custom JS on a subdomain, vs. someone just opening up the developer console and running whatever JS they like? Does JS loaded from the server have different privileges to JS entered at the console?
These days if you try and paste JavaScript to your address bar (try it with: javascript:alert(1);) then the browsers try and stop you. Firefox just won't execute any JavaScript, even if you've manually typed it. IE and Chrome strip the "javascript:" prefix (but Chrome is vunerable if you type "j" and paste the remainder).
More info here: https://www.facebook.com/photo.php?v=956977232793
[1] http://security.stackexchange.com/questions/12412/what-cooki...
Supports TFS and Git vestion-control
Free collaborative projects for up to 5 people
Can have closed-source projects
Why is it obvious that httpOnly cookies should go first?
if it's obvious for you — you are good at security. But it is NOT a common sense to use reset session
want a personal proof? $3000.
your posts are so entertaining, keep it up