3 ms·
Clickable link: https://gist.github.com/kailan/9f37ec2cd76314f945dda65e5beab241 https://gist.github.com/kailan/9f37ec2cd76314f945dda65e5beab... Very interestin
by graystevens 9y ago
Clickable link: https://gist.github.com/kailan/9f37ec2cd76314f945dda65e5beab241 https://gist.github.com/kailan/9f37ec2cd76314f945dda65e5beab...
Very interesting. I wonder if any private organisations setup a pseudo/canary repositories, that when pulled triggered an alarm? Or simply contained some monitored API keys or credentials to spot any activity/Insider threats.
Might be a neat idea for those businesses that are concerned about their private repos (either cloud hosted or self hosted).
May have picked up if anyone was able to exploit this.