Github is, for better or worse, a high-value target these days. Compromise of a Github account will often get you credentials which you can use to compromise high-value targets, for example production machines.
(Example from the Rails world: if someone gets read access to your git repository, expect them to figure out your secret token which you use for HMACing sessions to prevent forgery. If an attacker can forge sessions, they have remote code execution on your production servers. You can assume they will go directly from code execution to root on those servers, and from root on those servers to a systemic compromise of your entire network (if they want to do that).)
Use your imagination on what a mass compromise of accounts gets you. The simplest possible example is grepping for /bitcoin/, finding the full source code and credentials for a Bitcoin exchange, and rooting them then emptying the hot wallet. That results in fairly obvious economic advantage, right? You could also use scriptable attacks to root thousands of big-n-beefy production machines on fairly trusted IP addresses, then add them to a botnet, which you'd use for spamming or various other nefarious activities.
Then, even farther down the list, you have a dedicated adversary actually go through every repository they got access to and look for something uniquely fun to do with that particular target.
If you were looking to do industrial espionage on a particular target, you'd probably pick a way that was less likely to be detected and cause a company-level security response. (Use passive recon to identify one or a few likely target email addresses, find one or a few likely passwords for them, and try them first. Heads you win, tails you just left evidence in a log of perfectly normal user behavior. You might follow up this perfectly normal user behavior with a social engineering attack.)
Yeah, spear phishing / social engineering makes more sense for industrial espionage.
I am weakly confident, on the basis of some spelunking in the Rails internals in February, that if you get attacker chosen data into the session you're uniformly hosed on (at least) Rails 2 and Rails 3.
I wonder if you could expand on this? I'm not too knowledgeable about Rails or security, so I'd wonder how that works?
See: http://www.exploit-db.com/exploits/27527/
This can be done in an entirely automated fashion and requires no knowledge of the application other than the session's secret key.
In theory, an additional precaution one could take: change the default session serializer to `JSON`. By using `JSON` instead of `Marshal`, you're limited to storing strings, hashes and arrays in the session, but that's a good thing. The remote code execution vulnerability takes advantage of `Marshal` deserializing the session and loading objects deep within the Rails process in order to run arbitrary code. Take away that ability by using `JSON` instead of `Marshal` and you should no longer have to worry about this particular attack vector.
After a brief spelunk of the Rails codebase (and not getting very far, my laptop bricked itself today) there doesn't seem to be an easy way to do this, apart from finding the instance of `ActiveSupport::MessageVerifier` in your rails process and then running something like `verifier.instance_variable_set(:@serializer, JSON)`.
"We have reviewed our logs and it doesn't appear that any actions were taken by the attacker other than to authorize the 'GitHub XRP Giveaway' application against your account.
You should be able to find the OAuth events for that application in your account's security history:
https://github.com/settings/security
We do not believe that the application's authors were responsible for the break-in, rather that the attackers were attempting to game the giveaway.
Ripple's explanation of the giveaway can be found here: https://ripple.com/blog/git-in-the-game-2020-xrp-giveaway-fo...
As of this comment, 2020 RXP is worth ~ 0.03 BTC. Multiply by ~$500USD/BTC and you get ~$16 USD (over $20 when BTC was peaking $800+USD/BTC in the last couple days). Multiply that by the number of compromised accounts that meet the cutoff date criteria, and you get the take.
Potentially some good money depending on your success rate, but maybe not worth the cost of renting a botnet?
From the 3975 RXP I could send, it turned to ~85 USD the other day.
Multiply that by 1698 and you get $167k. Pretty sure it was a win for them.
Where did you get the 1,698 figure -- was that the number of accounts compromised?
My password has not been reset by github but I have updated it anyway.
On a sidenote I think that is a very clear and well written overview with clear details and a nice reminder about a section of the site that I was not familiar with.
If the account has an email address connected to it, you can also try the password against the e-mail account. That can be worth quite a lot if it works.