Yummy cookies across domains
github.com
github.com
However, this is one of the rare blog posts that go on to educate the reader about the technical aspects of something (in this case -- cookie attack vectors) that they can put to use somewhere in their own projects. Unlike a high level gloating blog post that is meant to inspire awe in the readers about how awesome company X is doing thing Y.
A PoC of how you could clone private repositories, such as the github.com source code itself at github.com/github/github (as an assumed example)
I think they meant "within this few weeks period you could not fixate CSRF token"
That would do absolutely nothing. Here are the attacks:
1) log a person out by replacing the session cookie
2) make github slower by making all requests have to send a large amount of cookie data.
3) Log someone in to one of the attackers accounts. For instance I can create an account like `jResîg`, and log people into that account.
Adding an HMAC prevents 0 of 3. Moving github pages to a different domain solves all three problems.
(not used their services for ages, so there might be more overlap than i remember)