8 ms·
Content Injection Attack on GitHub
- dvh 2y agoWell done
- dayjaby 2y agoExplanation for this with a better link: https://news.ycombinator.com/item?id=40615804 https://news.ycombinator.com/item?id=40615804
- SebFender 2y agook that lego thing is far out... not that great but I guess it helps people understand - lol
- op00to 2y agoIt did not help me. A Lego castle with … a secret magical tunnel? Just explain things, no need to besmirch Lego in this case.
- sva_ 2y agoThat goes right onto my 'convoluted explanations that make things more complicated than they really are' stack.
- epr 2y agoFeynman's Razor
- alexvitkov 2y agoTo understand monads, imagine you're in the middle of an infinite ocean. The ocean represents possibilities, and each wave represents a choice. Monads are invisible fish that you can't see but guide your boat. You don't know where you're going, and the fish don't either. Sometimes, they lead you to islands of coconuts, but other times they take you to whirlpools. You have a magical net that catches these fish, but the net has holes, so not all fish stay. Monads are these fish that might or might not help you navigate the infinite ocean, depending on whether they feel like it.
- deleted 2y ago[deleted]
- rvnx 2y agoSource-code: https://raw.githubusercontent.com/younesbram/younesbram/main/readme.md https://raw.githubusercontent.com/younesbram/younesbram/main... (Injection in LaTeX math tags)
- LASR 2y agoSo this opened in my GitHub iOS app at first and I was confused.
- wokwokwok 2y agoYou can see in the commit log from on https://github.com/younesbram/younesbram/commit/4282312e4ec38ab20bb5469cc298b24e142d99d5 https://github.com/younesbram/younesbram/commit/4282312e4ec3... where the first PoC commit is pushed up. The thing I find interesting is that this wasn't a random discovered; like, you look at the first commit in the sequence and you'll see. > \ce{$\unicode[goombafont; color:red; pointer-events: none; ... ie. This isn't some random chance discovery. This is someone looking to use a specific exploit with the ```math tag, already certain that there's some way of doing it. How strange.
- rawling 2y agoThis isn't the source of it. I came across this on Twitter last night and traced it back a bit to try to share "the original" with my colleagues. The earliest I found was https://x.com/cloud11665/status/1799136093071163396 https://x.com/cloud11665/status/1799136093071163396 which I think is slightly earlier than the second commit on this repo.
- mesmertech 2y agothat was the first iteration of CSS injection that was working, that github then patched. The new one is the new iteration that still works it was found by a bunch of anime-pfps on twitter and went "viral"
- DaiPlusPlus 2y ago> it was found by a bunch of anime-pfps on twitter I think you mean “infosec professional”
- pindab0ter 2y agoWhat does one's pfp matter, if what they found holds water?
- sshine 2y agoWhat’s a pfp?
- janmo 2y agoFunny at first, but this could have been exploited maliciously by let's displaying a message telling the user he has been disconnected and redirecting him to a phishing page.
- _lvbh 2y agoDoes this still work? Opened in Safari and don’t see anything out of place
- rawling 2y agoGone for me now in Android Chrome. I get this in what looks like an error box > Extra open brace or missing close brace
- lawgimenez 2y agoNot anymore on Firefox.
- a1o 2y agoYou need to look into the webarchive linked above as it was fixed already
- mmsc 2y agoOther than I love Samy, are many real-world examples of XSS being exploited for massive takeover of some service? I can't say I remember any news of a "website/service totally taken over due to XSS."
- shakna 2y agoXSS tends to be the first step in a chain of exploits. There are examples of using it for account takeovers, but XSS being the first step, usually means it doesn't get called out directly. The particular chain sequence gets a name, and that is what gets put out in media responses.
- mmsc 2y agoYes, finding some PoC for account takeover or something that involves XSS is cool and whatnot, but I'm asking whether these theoretical chain of exploits have ever actually been documented as being exploited to a significant degree.
- kevindamm 2y agoYou have to look a little further back into mid-2000s to see larger impact XSS attacks, but each FAANG has had to recover from them. I'm on mobile right now but I'll look for some examples later. What most companies realize early on is that you can't guarantee you'll prevent an XSS from slipping through. But, having a good template engine that sanitizes all strings automatically is good enough preventative measure, and putting all user-submitted content on a different subdomain or domain (like usercontent[dot]company[dot]com) with browser same-origin policy and perhaps CORS rules, will be enough to keep the impact contained. From there, just about everything else can be categorized as user error.
- thomas34298 2y agoI'd say a strict Content Security Policy (at least script-src 'self' WITHOUT unsafe directives) is even more important to keep the impact contained, so you'd have to put your scripts into separate files - as opposed to using inline scripts. It obviously won't help against "HTML injection" in general, but will shield your users from malicious scripts as long as you make sure that an attacker can't just upload scripts on the permitted origin(s).
- pandaxtc 2y agoI think the \unicode CSS injection used here was reported to the MathJax library a few months ago - https://github.com/mathjax/MathJax/issues/3129 https://github.com/mathjax/MathJax/issues/3129
- tempodox 2y agoI don't get this. It shows some mangled text that looks like defaced CSS, accompanied by the error message “Extra open brace or missing close brace”. How is this content injection? But the rescue murloc is cute.
- rvnx 2y agoGitHub just fixed the issue right now, the markdown you can see was injecting new background to the page, floating GIFs everywhere, etc.
- arshxyz 2y agoThey fixed the issue but for a beautiful moment in time, it looked like this: https://archive.is/LPC5O https://archive.is/LPC5O
- sizzle 2y agoLooks like my old MySpace
- 1023bytes 2y agoLooks like this has been patched
- fscaramuzza 2y agoGH just fixed it, but there's a snapshot from few hours ago: https://web.archive.org/web/20240608060046/https://github.com/younesbram/younesbram https://web.archive.org/web/20240608060046/https://github.co...
- pheatherlite 2y agoThat's an impressive turnaround.
- noman-land 2y agoBrilliant
- tyzoid 2y agoIt's still working for me on the live site
- whamlastxmas 2y agoShame that either GitHub doesn’t have a bug bounty, or their program isn’t good enough to entice people to use it
- moritzwarhier 2y agoSaw this last night (in Europe), was posted with a different image https://news.ycombinator.com/item?id=40614571 https://news.ycombinator.com/item?id=40614571 but that one of course stopped working too working snapshot (mildly nsfw): https://web.archive.org/web/20240607215223/https://github.com/stong https://web.archive.org/web/20240607215223/https://github.co... there's another one from 2 hours earlier but that misses the cool rotating cube.
- deleted 2y ago[deleted]