4 ms·
Please see my other comment. You cannot get user login information from Pages.
by defunkt 18y ago
Please see my other comment. You cannot get user login information from Pages.
- gojomo 18y agoIn some browsers, there's currently a way: Safari and IE (but not FF or Chrome) will display 'text/plain'-served-content as HTML. That means the GitHub 'raw' view of project content can be used to execute arbitrary user JS from github.com. Such JS can get at a logged-in user's name and make (at the very least) superficial changes to profile information. A harmless demo (works on Safari and IE) is here: http://github.com/gojomo/scratch/raw/master/getuser/index.html http://github.com/gojomo/scratch/raw/master/getuser/index.ht... Trivially, then, a Pages subdomain can use the above in an iframe to export the username out. Demo: http://gojomo.github.com/getuser http://gojomo.github.com/getuser The 'raw' issue seems more serious and isn't affected by whether Pages are on .github.com subdomains or not. Still, subdomains have a slight leg up on exploiting any security slip-ups and browser bugs that may occur.
- defunkt 18y agoNot a problem in Safari 3. URL 1 in Safari: http://img.skitch.com/20081222-kr2k6gwm1b8cbt3i7xqy6n5x9c.png http://img.skitch.com/20081222-kr2k6gwm1b8cbt3i7xqy6n5x9c.pn... URL 2 in Safari: http://img.skitch.com/20081222-dk57nxe9epdxx9u5gt71gu1u4p.png http://img.skitch.com/20081222-dk57nxe9epdxx9u5gt71gu1u4p.pn... Please report security bugs at http://support.github.com http://support.github.com - not in old Hacker News comments which may never been seen. Thanks.
- gojomo 18y agoSorry, should have specified: Safari 3 on Windows. All my tests were on Windows, none on MacOS or Linux. If it hadn't still been your 'topmost' comment, and a recent top story possibly still monitored by multiple GitHubbers -- or if I hadn't received an ack by this morning -- I would have tried an alternate means of report. Or, if I thought this was a higher-risk issue. (Your general user-management already seems well-fortified by https against all but superficial mischief.) Still, I understand the preference that a security bug however small be reported directly first, and I'll respect that in the future.