6 ms·
Something @chrislloyd and I found in Github. Nothing too serious!
by Stuk 16y ago
Something @chrislloyd and I found in Github. Nothing too serious!
- aeden 16y agoI'm sure the folks at Github will fix it today since you've emailed them. Cute use of rickrolling btw. :-)
- mrspeaker 16y agoWere you actively searching for it, or did you discover it by accident?
- chrislloyd 16y agoDiscovered it by accident, was perusing https://github.com/jnicklas/xpath https://github.com/jnicklas/xpath and saw that the message was, well, editable.
- mike-cardwell 16y agoA nice POC would have been to write some XSS code which adds your SSH key to a users account if they're logged in when viewing the XSS. I wonder how many HN'ers that would have affected, and git repositories that would have exploited. I don't think it is an exageration to say that an XSS flaw on something like github has the potential to be disasterous.
- durin42 16y agoThat actually sounds like an awful way to report an XSS. Honestly, as someone that maintains a web service I have to say I'd prefer private disclosure than even the rickroll approach. All it takes is one "genius" doing some copy-paste action and then you're in a world of hurt and damage control.
- mike-cardwell 16y agoRegarding this and the other response to me. I would never do what I described. I was just trying to demonstrate to those that don't understand XSS properly, that these issues are serious. I don't think a Rick Rolling really gets that issue across. If I do an XSS attack against you on github whilst you are logged in, I can compromise all of your source repositories, your code, and in turn, potentially compromise the systems of your users.
- durin42 16y agoEnd-users aren't who you need to tell. Just site owners. Posting this to HN before it was fixed constitutes (IMO) completely irresponsible disclosure.
- mike-cardwell 16y agoI agree. I would not have disclosed this particular XSS flaw until after it was fixed.
- patio11 16y agoXSS trivially compromises your cookie. If I have your cookie, I am you. Demonstrating cute ways to do things that I could just do by logging in as you is superfluous. Even doing that as a prank would cause a Big Red Button security audit at some companies. As in, drop what you're doing, we need to go over every line of every commit in the git repo and verify nothing like a server password was committed. Recommendation #1 from that audit will be to stop using github.
- pilif 16y agoyou wouldn't get access to the cookie in most browsers. The github session cookie is apparently marked as httponly in which case JS wouldn't see it.
- patio11 16y agoI wouldn't trust that, since there are many paths to the cheese besides document.cookie. For example, Firefox (IIRC) will let Javascript inspect all headers from an Ajax request. The cookie is just another string there...
- mike-cardwell 16y agoIs that actually possible, or are you just pondering that it might be? If Firefox lets you access the raw HTTP Cookie header of a http-only cookie via AJAX, I would consider that a security bug, and report it... I may take out 10 minutes to have a play with that later if nobody else checks first...
- patio11 16y agoI have personal knowledge that it was possible in 2007. I don't keep abreast of developments in browser security that make them more secure: unlike, say, Thomas and the geniuses at Matasano, all I need to know is the worst possible consequence of whatever our wonderful outsourcing partners dreamed up this time. XSS was one step below server-side code execution on our severity scale. [Edit: This was apparently fixed in 2009 in Firefox. http://www.mozilla.org/security/announce/2009/mfsa2009-05.html http://www.mozilla.org/security/announce/2009/mfsa2009-05.ht... Again, that is just one vector -- I still think HttpOnly is likely insufficient.]
- ortatherox 16y agoseems to be already fixed, isn't doing anything for me (chrome / osx)
- troels 16y agoHover over the "message" column in the file list.
- deleted 16y ago[deleted]
- chrisbroadfoot 16y agoWhy do you think it's nothing too serious?