13 ms·
How I hacked Github again
- desireco42 13y agoOne more comment. Security flaws seem obvious, but getting security right is hard. It require a lot of testing and effort to get everything right. This kid Homakov has a talent for finding holes and seems that has his hard on right place ie. isn't abusing it.
- comrade1 13y agoSomething I don't really understand is why people use github in the first place when it's so easy to set up your own git repos with gitolite. I understand using github for large open source projects that you want people to freely branch, but it seems the vast majority of accounts are small personal projects and even some small companies.
- interstitial 13y agoHalf the comments are about his pay scale, imagine the ruckus if he had been paid in unwithdrawable bitcoins at mtgox.
- Einstalbert 13y ago$400 is such chump change compared to the PR disaster that can come from exploited, or even just leaked, vulnerabilities. I honestly think any SaaS needs to have this somewhere in their budget once a year.
- rip747 13y agoevery post this guy has about the security holes he has found are impressive to say the least.
- gabrtv 13y agoImpressive display of persistence, stringing together those vulnerabilities. I also see your English has gotten noticeably better :) Keep up the good work!
- TomaszZielinski 13y agoNot suggesting anything, but "your" might be the key here :-)
- aroman 13y agoWow, really clever stuff! Also of note is the $4,000 reward he received from GitHub's bounty program — their largest to date, according to the email.
- sdegutis 13y ago> $4000 reward is OK. $4000 !? Wow, I'd love to be able to make $4000 on the side just doing what I love. > Interestingly, it would be even cheaper for them to buy like 4-5 hours of my consulting services at $400/hr = $1600. This sounds like a pretty clever strategy for marketing yourself as an effective security consultant. EDIT: $4000!? wow. so money. such big.
- coherentpony 13y agoAccording to his website, the minimum time you can buy services for is 8 hours so I'm not sure what he means here.
- claudius 13y ago8 hours at 400$/hour will still only be 3200$ and he can presumably spend the remaining 4-3 hours doing more security analysis with less overhead, so it might still be cheaper to hire him as a consultant.
- arnarbi 13y agoBut they'd have to pay those $3200 without knowing if there were results. They might have to pay dozens of such consultants before one of them found bugs like this. Bug bounties, paid only on successful discoveries, are much cheaper.
- aidos 13y agoBut also much riskier. What if it transpires that the $4000 isn't enough? We know roughly what they're paying now, so when people find an issue like this they know they could sell it for much more.
- shawabawa3 13y agoOf course, there's probably also a large chance that he finds nothing in those 8 hours
- ChuckMcM 13y agoGrats Egor, once again a great explanation of how these things add up into vulunerabilities.
- thrush 13y ago"Btw it was the same bug I found in VK.com" Is there an easy way to see what vulnerabilities other websites have had and fixed, and to check if your site has them as well?
- nightpool 13y agoAs soon as I saw the new bounty program the first thought through my head was "Any Github Hacking leaderboard without homakov at tthe top is an inaccurate one". Congrats on your newest discovery!
- intortus 13y agoShame on github for making these mistakes in the first place, but kudos to them for doing such a great job of engaging the white hats.
- akerl_ 13y agoIf we're shaming any code with security flaws, no one is free of shame. I'm excited by the bounty program, it's a great way to get things like this identified and responsibly disclosed
- intortus 13y agoI agree that flaws will always exist, but I don't understand why it's ever worth it to not be absolutely strict about matching redirect_uri in OAuth.
- homakov 13y agoIt's hard to shame github for those bugs. All of them are low-sev separately, only together they make sense.
- shill 13y agoNice work Egor. I hope to see a GitHub client testimonial on sakurity.com sometime soon.
- patcon 13y agoSorry, but this is a terrible approach to thinking about progressive and open security practices...
- livingparadox 13y agoSeeing stuff like this, I want to get into comp-sec. It always sounded interesting, and it looks like it pays well...
- shill 13y agoIt pays well if you are the guy that has hacked GitHub twice.
- Anderkent 13y agoRemember that you only see the interesting stories and successful investigations. Before making such a decision you should try to arrange a chat with someone already doing comp-sec, and figure out how much time they spend on all the other stuff.
- knocknock 13y agoAnyone know some good beginner reading material for someone interested in learning this kinda stuff?
- big_youth 13y agoI recommend grabbing a copy of Web Application Hackers Handbook[0] and try hacking vulnerable vm's[1]. I see that your a sysadmin so if network hacking is more you speed I would download Metasploit[2] and start hacking old linux or windows distros. [0]http://www.amazon.com/The-Web-Application-Hackers-Handbook/dp/1118026470 http://www.amazon.com/The-Web-Application-Hackers-Handbook/d... [1]http://itsecgames.blogspot.com/2013/07/bee-box-hack-and-deface-bwapp.html http://itsecgames.blogspot.com/2013/07/bee-box-hack-and-defa... [2] http://www.metasploit.com/ http://www.metasploit.com/
- akerl_ 13y agoI'd put this in the same category as mobile app dev. There are a few people making money by the truckload, plenty of people making a decent living, and lots of folks who strike out. If it's something you're interested in, go for it. I just worry that people see this like the promise of gold in a faraway land and go rushing in, not thinking about the real distribution of success.
- mtkd 13y agoGithub should have hired him last time.
- jisaacks 13y agoMaybe they offered? Maybe he can make more consulting.
- kirubakaran 13y agoI think the parent means "hired as a consultant"
- akerl_ 13y ago"P.S.2 Love donating? Help Egor on coinbase or paypal: homakov@gmail.com" Maybe it's just me, but asking for donations after saying you bill clients at $400/hr seems weird to me. I wish I could bill at that rate.
- jmathai 13y agoNot everyone's time is equal. If you're finding security holes like Egor then an hour of your time is absolutely worth $400/hr.
- akerl_ 13y agoI totally believe that he's worth that amount of money. I'm sorry if you thought I was questioning that. I'm questioning the juxtaposition of his hourly rate with a request for donations.
- gatehouse 13y agoI think the contract makes sense for clients, and the donation makes sense for other security researchers who want an incentive for him to keep publishing ideas.
- jmathai 13y agoUnderstood. But I imagine that his work isn't quite as "steady" as one might expect. He invests time by trying to find security exploits in hopes that the affected company compensates him. He doesn't set his price or even determine if he gets paid for his time. I think that might be the rationale...or it might just be that he's found himself in a position where he can collect bounties AND donations :).
- homakov 13y agoThere's a number of people who would like donate but not interested in consulting.. There were always people complaining "Add a donate address" Now "why you added a donate address". Oh, Internet.
- jqueryin 13y agoIf @homakov is finding security holes without access to Github repositories, imagine what he'd find if you had him code audit for a few days... He's clearly been going about this the proper white-hat way and ensuring holes are patched before open disclosure... what's there to lose? On the flip side, you could go about doing what you're doing under the presumption nobody is maliciously targeting your user base. In this scenario, it's possible you have a couple bad actors that see a net benefit greater than your bug bounties and are silently stealing and selling supposedly secure code from your users. You could be supporting a hacker black market where they sell and trade codebases to popular online sites. Imagine how easy it would be for them to find vulnerabilities in these sites if given access to the source code. That, my friends, would be a catastrophe.
- GuiA 13y agoI don't get why Github just hasn't hired the guy already.
- throwaway3301 13y agoHow can I start learning about how to identify exploits like this? I know some basics about web application security and work as a software engineer on a day-to-day basis but security has always been a passion of mine and I have always wanted to be able to support myself through working on security alone (by collecting rewards through bounty programs, self-employed security consulting, working at a security consulting firm like Matasano, or some combination thereof) but I don't know where to start. I want to learn the ins and outs of web application security instead of just understanding the OWASP top 10 and having a strong interest in certain topics (like HTTPS/SSL vulnerabilities). When I read disclosures from people like Egor I grasp the steps they are taking to craft an exploit like this as they are explained but I don't know how to identify these exploits on my own. Can anyone recommend some reading material or some first steps I can take to work towards moving to a more security-focus career? Thanks.
- deleted 13y ago[deleted]
- big_youth 13y agoSee my comment below for Web App hacking, my personal favorite, but if you enjoy working in the lower level and reading assembly then the matasano ctf is very well made.
- rst 13y agoLike a lot of other things, practice matters. OWASP has some deliberately insecure webapps which are meant to give people practice spotting and exploiting vulnerabilities (WebGoat, RailsGoat, PyGoat, probably others). There are also "capture the flag" competitions of the sort run every so often by Stripe; Matasano currently has one going as well, focused on embedded systems: http://www.matasano.com/matasano-square-microcontroller-ctf/ http://www.matasano.com/matasano-square-microcontroller-ctf/
- jensC 13y agoMatasanos CTF is hard. At least I think so, but a good start anyway.
- Kiro 13y agoHow do you find all this stuff? Where do you even start?
- enscr 13y agoGithub uses ruby on rails, which is a pretty mature framework, perhaps covering most of the common security pitfalls. Additionally, I assume github has excellent programmers because of the nature of their job. Could someone explain in simple english, how did they overlook known & well documented bugs that got them hacked (e.g. Bug 3 about cross domain injection). I'm wondering if someone of Github's caliber can be hacked so easily, what about the rest of the masses developing web apps. Especially all those new crypto-currency exchanges popping up left & right. I've been toying with Django. Reading through the docs makes me feel that as long as I follow the safety guidelines, my app should be safe. It feels as if they've got you covered. But this post rattles my confidence.
- jim-greer 13y agoIt's worth mentioning that Github has forked Rails and is working off their own private branch of Rails 2.3. Not saying that was relevant to this exploit, mind you. https://github.com/github/rails https://github.com/github/rails http://www.kalzumeus.com/2013/06/17/if-your-business-uses-rails-2-3-you-need-to-move-to-a-supported-option-asap/ http://www.kalzumeus.com/2013/06/17/if-your-business-uses-ra...
- pjungwir 13y agoIt is relevant to this: > I . . . decoded _gist_session cookie (which is regular Rails Base64 encoded cookie) In Rails 4 the session cookie is encrypted with a server-side secret, so the end user can't decipher it.
- steveklabnik 13y agoIsn't gist an entirely separate application from dotcom? My impression was gist is a Sinatra app, not Rails.
- kneath 13y agoGist is indeed running Rails 4.
- 13y ago
- leandrocp 13y ago@homakov, have you thought about selling screencasts ?
- homakov 13y agoSecurity screencasts with Russian accent? HA HA.
- beambot 13y agoSure, why not? Notch does coding casts. And WhiteRa (SC2) makes some great casts, even (especially?) with his strong accent!
- d0m 13y agoWhiteRa on HN! You made my day : ) Just a quote while we're at it.. >> We make expand and then defense it.
- petepete 13y agoI'm pretty much sold!
- ionwake 13y agome too!
- deleted 13y ago[deleted]
- tortilla 13y agoI think it would add to the video. :)
- YuriNiyazov 13y agoEspecially with a Russian accent. Gives it a very "if you don't do like I say, other Russians will come and steal your shit" aura.
- peterwwillis 13y agoThis would be a great case study if expanded on and edited. Igor should write a book!
- pgs_pants 13y agoFirstly, well done. It is good to see well done security eval. But github, seriously? Why do you guys fail so hard at security? Too much Brogrammer rather than programmer methinks.
- korzun 13y agoIronically, you sound like a brogrammer.
- runn1ng 13y agoOK. I give up. No matter how much I try, I will never be as cool as @homakov.
- jbeja 13y agoThat no reason to give up, you are completely forbidden to do that >.<.
- outside1234 13y agowhy hasn't GitHub hired this guy?
- ultimoo 13y ago@homakov finds 5 different bugs with github and manages to align them so that a bigger vulnerability is exposed in under 5 hours? That's amazing! I used to think I'm a fast delivery-focused developer but I'm probably just a fraction of how fast some people are.
- phillmv 13y agoHe's not counting all the time he's spent carefully reading the oauth spec and playing with different options ;).
- lostlogin 13y agoOr the time he spent learning to get to the level of expertise he has. Maybe that is why his hourly rate is somewhat more than mine.
- allochthon 13y agoThis guy is like a good security QA guy on steroids.
- ng6tf7t87tyf 13y agoRuby Brogrammer Security Fail yet again. Friends don't let friends code in Fails frameworks.
- Omnipresent 13y agoIt would be great for educational purposes if a sample app was setup so this vulnerability could be tried on it. Most of the white hack vulnerabilities are fixed by the time white hat blog posts come out so there is no way to actually try them out.
- derengel 13y agoI'm the only that thinks that $4000 was very cheap on part of Github? a security hole like this on the wrong hands would have bring severe consequences to github, consequences so big that they would probably pay $1,000,000 USD for it to never happen. So maybe something in the $50-100K would sound more reasonable. Egor is a great hacker with no business sense? On the other hand, the publicity his service gets for this its probably worth more than $50-100K.
- nolok 13y agoNo you're not alone, considering this was a combination of security holes that allowed people to get read/write access to others repos, including private.
- philliphaydon 13y agoI'm really glad Github paid him, but reading what the exploit can do I really think he deserves more, sure they were a series of small exploits, but all together... they are pretty damaging in the wrong hands.
- ivanca 13y agoReally good work @homakov and I suggest you should start a web-security-school or something of the sort. I'm sure there is money in that field and you would be able to keep traveling around the world while doing it.
- desireco42 13y agoWhy is GitHub so hostile to this kid, just give him a job already! He obviously has deep understanding of how things work. I would feel better knowing he work for them.
- bliti 13y agoHe clearly states in his blog that full time employment is not his current focus. Prefers to consult.
- desireco42 13y agoI am consultant as well, I can be wooed with right offer and if I am interested in something. He obviously is interested in GitHub. I think they are still pissed off from last time when he found flaws.
- RickHull 13y agoHuh? Did you read the letter from github? It closes out: "Thanks again for your awesome work." http://2.bp.blogspot.com/-xqPTMgxhYmY/UvUCrsc9C8I/AAAAAAAADkg/Fe6N4AFxMWE/s1600/Screen+Shot+2014-02-07+at+10.58.16+PM.png http://2.bp.blogspot.com/-xqPTMgxhYmY/UvUCrsc9C8I/AAAAAAAADk...
- deleted 13y ago[deleted]
- nakovet 13y agoOne thing that I didn't get from the post: > Oh my, another OAuth anti-pattern! Clients should never reveal actual access_token to the user agent. From what I understood by reading the OAuth RFC is that front-end intensive applications (a.k.a. public client) should have short lifespan access tokens (~ 2 hours) and the back-end takes care of reissuing a new access token when expired. Can someone clarify on how to make a those calls from a front-end application without revealing the access token?
- homakov 13y agoBut gist is not a front end app. Gist has web frontend and Rails backend, which is supposed to store the token safely.
- afarra 13y agoDoes anyone know of a website or central resource that documents all these vulnerabilities to look out for?
- syshax 13y agoStart here: https://www.owasp.org/index.php/Top_10_2013-Top_10 https://www.owasp.org/index.php/Top_10_2013-Top_10
- Tobu 13y agoWTF is up with Firefox and Chrome not fixing their /// bug. They're prioritising neither user security nor standards-compliance.
- homakov 13y agoOh, there are tons of other silly wontfixes. I gave up. They really don't care about web apps. E.g. instead of /../ i could have used /%2e%2e/!
- deleted 13y ago[deleted]
- yarou 13y agoVery cool write-up of non-critical bugs that can be used together to inflict some serious damage. Great work @homakov!
- bashcoder 13y agoThanks for continuing to make Github safer for all, @homakov. Someday I might even host a private repo there again, but I haven't done that since your first mass assignment exploit. You continue to prove that my decision was a good one.