7 ms·
XSS vulnerability found in Github
- Stuk 16y agoSomething @chrislloyd and I found in Github. Nothing too serious!
- aeden 16y agoI'm sure the folks at Github will fix it today since you've emailed them. Cute use of rickrolling btw. :-)
- mrspeaker 16y agoWere you actively searching for it, or did you discover it by accident?
- chrislloyd 16y agoDiscovered it by accident, was perusing https://github.com/jnicklas/xpath https://github.com/jnicklas/xpath and saw that the message was, well, editable.
- mike-cardwell 16y agoA nice POC would have been to write some XSS code which adds your SSH key to a users account if they're logged in when viewing the XSS. I wonder how many HN'ers that would have affected, and git repositories that would have exploited. I don't think it is an exageration to say that an XSS flaw on something like github has the potential to be disasterous.
- durin42 16y agoThat actually sounds like an awful way to report an XSS. Honestly, as someone that maintains a web service I have to say I'd prefer private disclosure than even the rickroll approach. All it takes is one "genius" doing some copy-paste action and then you're in a world of hurt and damage control.
- mike-cardwell 16y agoRegarding this and the other response to me. I would never do what I described. I was just trying to demonstrate to those that don't understand XSS properly, that these issues are serious. I don't think a Rick Rolling really gets that issue across. If I do an XSS attack against you on github whilst you are logged in, I can compromise all of your source repositories, your code, and in turn, potentially compromise the systems of your users.
- durin42 16y agoEnd-users aren't who you need to tell. Just site owners. Posting this to HN before it was fixed constitutes (IMO) completely irresponsible disclosure.
- mike-cardwell 16y agoI agree. I would not have disclosed this particular XSS flaw until after it was fixed.
- patio11 16y agoXSS trivially compromises your cookie. If I have your cookie, I am you. Demonstrating cute ways to do things that I could just do by logging in as you is superfluous. Even doing that as a prank would cause a Big Red Button security audit at some companies. As in, drop what you're doing, we need to go over every line of every commit in the git repo and verify nothing like a server password was committed. Recommendation #1 from that audit will be to stop using github.
- pilif 16y agoyou wouldn't get access to the cookie in most browsers. The github session cookie is apparently marked as httponly in which case JS wouldn't see it.
- patio11 16y agoI wouldn't trust that, since there are many paths to the cheese besides document.cookie. For example, Firefox (IIRC) will let Javascript inspect all headers from an Ajax request. The cookie is just another string there...
- mike-cardwell 16y agoIs that actually possible, or are you just pondering that it might be? If Firefox lets you access the raw HTTP Cookie header of a http-only cookie via AJAX, I would consider that a security bug, and report it... I may take out 10 minutes to have a play with that later if nobody else checks first...
- patio11 16y agoI have personal knowledge that it was possible in 2007. I don't keep abreast of developments in browser security that make them more secure: unlike, say, Thomas and the geniuses at Matasano, all I need to know is the worst possible consequence of whatever our wonderful outsourcing partners dreamed up this time. XSS was one step below server-side code execution on our severity scale. [Edit: This was apparently fixed in 2009 in Firefox. http://www.mozilla.org/security/announce/2009/mfsa2009-05.html http://www.mozilla.org/security/announce/2009/mfsa2009-05.ht... Again, that is just one vector -- I still think HttpOnly is likely insufficient.]
- ortatherox 16y agoseems to be already fixed, isn't doing anything for me (chrome / osx)
- troels 16y agoHover over the "message" column in the file list.
- deleted 16y ago[deleted]
- chrisbroadfoot 16y agoWhy do you think it's nothing too serious?
- mike-cardwell 16y agoDidn't work for me. Then I remembered to tell noscript to enable js. Does anyone still need convincing that they should be using noscript?
- robryan 16y agoHow do you browse though given that the vast majority of modern websites made use of javascript?
- 16s 16y agoWith noscript, browsing still works fine, you just have to explicitly allow the javascript you want/need rather than allowing just any site to execute code in your browser.
- steveklabnik 16y ago... so if I want to XSS you, I just have to do it on a site that requires JS to function. Don't get me wrong, I can appreciate reducing your attack surface... but noscript just doesn't seem like that great of an idea, still.
- jrockway 16y agonoscript is per-source, so you can whitelist their <script> blocks and jquery.js, but that random javascript in an onmouseover in a forum comment will do nothing.
- steveklabnik 16y agoFair enough. Seems like a whole lot of effort for very little gain.
- deleted 16y ago[deleted]
- deleted 16y ago[deleted]
- troels 16y agoYou didn't report it to them?
- deleted 16y ago[deleted]
- jrockway 16y agoRighteous indignation? You defaced their site. The least you can do is say, "hey, I fucked up your site, here's how". Otherwise you are basically a 4chan script kiddie. Nice delete.
- mml 16y agoHi, since you were so incensed by my irresponsible, unethical, and down-right evil behavior, that you saw fit to call me a 4chan script kiddie (horrors!), just thought you'd like to know: From: "Chris Wanstrath" <chris@redacted.org> To: mml Subject: Re: security hole In-Reply-To: <0228F552-5269-4F44-9D77- 82F077DE2242@redacted.com> MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline References: <0228F552-5269-4F44-9D77-82F077DE2242@mml> Thanks, fixed! On Wed, Mar 26, 2008 at 3:54 PM, <mml> wrote: > hi, > > github needs to clean up it's xss act: > > > http://github.com/redacted > > > -mml -- Chris Wanstrath http://github.com/defunkt Cheers, -mml
- jrockway 16y agoI don't really care, I just took exception to your use of the expression "righteous indignation". By default, people are friends here, and the person who you replied to was a little surprised that you would just mess with github with no intent to help them fix it. You wouldn't go into your friend's living room, shit all over it, and leave, right? People read your post and were a little surprised that you would do the equivalent to github. (Maybe you didn't, but your tone conveyed that you did.) Anyway, thanks for clearing this up!
- Garbage 16y agoNot working for me. Is it fixed? I can see only JavaScript. IE8 on Windows XP.
- pilif 16y agomouse over the message in the file list.
- pilif 16y agoThis might look really funny, but consider this: The javascript you are executing there runs on the github domain. So it can do whatever you can do by manually clicking. The injected script could for example submit a new SSH public key for your account (doesn't require your password again). Or just be funny and delete repos. Or just upgrading your account to a bigger, more expensive plan. Or they could get a list of your private repositories. Combine that with the upload of a new private key and you'll get free access to proprietary code of any account. Aside of fixing the XSS issue, they really should ask for the password again when uploading a public key.
- chrisbroadfoot 16y agoSeems to be fixed now. Quick work by the github guys, kudos. For those who missed it, the title attribute inside commit messages in the file list wasn't HTML encoded.
- mike-cardwell 16y agoThey should be able to look at their database to determine if anyone else has has used this method to inject arbitrary html into a page in the past. They should then put up a notice on their website to describe what happened, describe how they confirmed that this flaw hasn't been exploited previously, and describe what measures they will take in future to prevent this sort of problem. In my opinion, that is how a "good", company would react. Anything less would be a disappointment.
- tjarratt 16y ago|In my opinion, that is how a "good", company would react. This is (more or less) how Github has reacted to security issues in the past. However, at the moment this seems to be a fairly small exploit, that wasn't aggressively used by any would-be exploiters. I definitely don't think github should put up a notice for this. Would you really want to be alerted every time a website you used closed a minor security hole, that had possibly never even affected anyone? They absolutely should, if any user information was leaked, or if there was downtime involved, but you honestly do not need to keep informing users about this sort of mundane security update. At best, I would suggest it go on their blog. Not reporting "oh we found an xss hole that maybe one or two people had used before." is NOT a disappointment.
- bl4k 16y ago> that wasn't aggressively used by any would-be exploiters. Doesn't matter. A response shouldn't be measured according to how widely a security hole was exploited, it should always be responded to with full information and transparency.
- mike-cardwell 16y ago