4 ms·
The author fails to acknowledge a scenario where you wouldn't care, or where you'd even actively want your source code to be public. For example, static websit
by libeclipse 9y ago
The author fails to acknowledge a scenario where you wouldn't care, or where you'd even actively want your source code to be public.
For example, static websites for open source projects, et al.
- codezero 9y agoI think they did... > It seemed like an accessible git repository was intended on some websites - mostly open source projects where the website’s sourcecode is available online.
- ubernostrum 9y agoEvery so often, the Django security address gets an email from someone who wants to claim bug-bounty money because "Dear Django team, I have discovered source-code disclosure vulnerability in your web site..."
- xg15 9y agoEven then though, they should be aware of the meta data that's stored in the repo and make sure it's appropriately sanitized. > On the other side, we had to hold our breath when we noticed that more than 100 projects used HTTP-Authentication for server-client communication. That means, that the protocol://user:password@host/repository combination is saved in the .git/config file, giving attackers access to the users (companies) GitLab-instance or GitHub/BitBucket account. With a bit of luck an attacker gets access to the CI-Server and then runs malicious code to further compromise your infrastructure.