3 ms·
They used a heif payload to get server access but they never describe the SSO flaw they used to actually get repo access (the juicy part!), bummer! Wish they s
by sergiotapia 11d ago
They used a heif payload to get server access but they never describe the SSO flaw they used to actually get repo access (the juicy part!), bummer!
Wish they shared that interesting piece since that's the interesting part.
Also pretty shocking that openai uses github. I would have expected a company of that size with that much to lose would be using self hosted stuff.
- carstonh 11d agoagreed… why can an ID token for a separate client application be used to read and write to GitHub? that’s the story here.
- jsiepkes 11d agoNot checking the "audience" of a token or misconfiguring it is pretty common. A lot of applications don't actually check it.
- 6thbit 10d agosince it was sso for their codex/chatgpt account, presumably they used an existing chatgpt github connector available to such accounts. Somehow the auth'd token for the forum was available within that VM, so having RCE they could've replayed it? idk