TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Github seems to be experiencing security issues

60 pointsby sylvainkalacheover 11 years ago

24 comments

wgxover 11 years ago
The list of IPs from China (&amp; Indonesia, etc) - that most are seeing on their page - making failed login attempts, looks like a botnet or automated bruteforce on the GitHub authentication service. Hit enough usernames with a dictionary attack and they&#x27;ll get some accounts. I assume that GH are doing some basic rate-limiting or &#x27;fail2ban&#x27; style blacklisting on these attempts.<p>As anyone who&#x27;s put an EC2 up without securing it knows, an automated SSH attempt at &#x27;root&#x27; will be made within a few hours of it coming online.
评论 #6760087 未加载
评论 #6760327 未加载
评论 #6760286 未加载
评论 #6760487 未加载
notwedtmover 11 years ago
A reply from Zach Holman on twitter confirms that it&#x27;s an automated attack that they are currently working on mitigating: <a href="https://twitter.com/holman/status/402720736650874880" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;holman&#x2F;status&#x2F;402720736650874880</a>
awjrover 11 years ago
I would strongly suggest people enable two factor authentication: <a href="https://github.com/settings/two_factor_authentication/configure" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;settings&#x2F;two_factor_authentication&#x2F;config...</a>
评论 #6760173 未加载
ThatOtherPersonover 11 years ago
I just checked my account&#x27;s security history, and there&#x27;s been a failed login attempt every 7 hours for the past two days, all from different IP addresses.<p>It reminds me of the &quot;Hail Mary Cloud&quot; posted previously on HN - <a href="http://bsdly.blogspot.com/2013/10/the-hail-mary-cloud-and-lessons-learned.html" rel="nofollow">http:&#x2F;&#x2F;bsdly.blogspot.com&#x2F;2013&#x2F;10&#x2F;the-hail-mary-cloud-and-le...</a>
aramover 11 years ago
Very strange; I just checked my security history and see that there have been 5 unsuccessful login attempts from China&#x2F;Venezuela to my account (last 14 hours). Everything before that is pretty clean and without fake logins.<p>Does anyone have more information on this?
评论 #6759928 未加载
评论 #6760063 未加载
评论 #6760265 未加载
评论 #6760342 未加载
评论 #6759969 未加载
评论 #6760476 未加载
评论 #6760574 未加载
aaronpkover 11 years ago
I don&#x27;t get it... this is my own security page which looks normal to me.<p>[edit] I see one failed login attempt from a chinese IP like other people are saying. Maybe that is what OP meant to point out?
评论 #6760784 未加载
评论 #6760024 未加载
sebslomskiover 11 years ago
user.failed_login: Originated from <a href="http://ipinfo.io/190.203.225.87" rel="nofollow">http:&#x2F;&#x2F;ipinfo.io&#x2F;190.203.225.87</a> 12 hours ago<p>user.failed_login: Originated from <a href="http://ipinfo.io/186.88.197.206" rel="nofollow">http:&#x2F;&#x2F;ipinfo.io&#x2F;186.88.197.206</a> 18 hours ago<p>user.failed_login: Originated from <a href="http://ipinfo.io/182.253.48.4" rel="nofollow">http:&#x2F;&#x2F;ipinfo.io&#x2F;182.253.48.4</a> a day ago<p>user.failed_login: Originated from <a href="http://ipinfo.io/94.134.190.4" rel="nofollow">http:&#x2F;&#x2F;ipinfo.io&#x2F;94.134.190.4</a> a day ago<p>user.failed_login: Originated from <a href="http://ipinfo.io/186.94.244.213" rel="nofollow">http:&#x2F;&#x2F;ipinfo.io&#x2F;186.94.244.213</a> 2 days ago<p>user.failed_login: Originated from <a href="http://ipinfo.io/109.122.92.52" rel="nofollow">http:&#x2F;&#x2F;ipinfo.io&#x2F;109.122.92.52</a> 2 days ago
jibsenover 11 years ago
Not sure if it&#x27;s related to what the OP meant, but I can see 5 failed login attempts from different IP addresses over the past 48 hours (and pretty much none before that).
SilkRoadieover 11 years ago
Why does this page mean GitHub is experiencing security issues?<p>I didn&#x27;t know this page existed. Its pretty handy, though I don&#x27;t like how it shows failed logins. 6 attempts in the past 24 hours unnerves me. Probably trying my email and my use-all password from vBulletin or one of the numerous other sites which have been broken into.
评论 #6759943 未加载
segover 11 years ago
It&#x27;s showing a page of security history. That doesn&#x27;t mean there is a problem with security. It&#x27;s just for the curious ones, or the paranoid ones, or those that surf around on suspicious networks or committed something last night and can&#x27;t remember it at all.<p>It&#x27;s just a reality check.<p># my $0.02
mekishizufuover 11 years ago
Hmm, 13 failed attempts for me as well. Glad I have the &quot;Two-factor authentication&quot; On just in case.<p><a href="https://github.com/blog/1614-two-factor-authentication" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;blog&#x2F;1614-two-factor-authentication</a>
simonwover 11 years ago
I wonder if these failed login attempts are using passwords from the Adobe breach.
评论 #6760012 未加载
antrover 11 years ago
Same here<p><pre><code> 6 hours ago user.failed_login: Originated from 190.237.42.139 12 hours ago user.failed_login: Originated from 186.91.131.199 16 hours ago user.failed_login: Originated from 91.226.79.82 a day ago user.failed_login: Originated from 184.22.105.99 a day ago user.failed_login: Originated from 190.205.97.211 2 days ago user.failed_login: Originated from 189.43.19.210</code></pre>
matthewbadeauover 11 years ago
Looks like some of the IPs are proxies: <a href="http://webcache.googleusercontent.com/search?q=cache:HIFaDGufvkcJ:venezuela-proxy.blogspot.com/2013/11/live-proxy-list-on-november04-2013.html&amp;client=firefox-a&amp;hl=en&amp;gl=us&amp;strip=1" rel="nofollow">http:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache:HIFaDGu...</a>
thezilchover 11 years ago
Strangely, I use a unique email for github, like I do with most sites that allow attaching &quot;+comment&quot; to the localpart of email addresses. Are attackers really this sophisticated, or where did they get the list?<p>Edit: Nevermind, I guess github allows authenticating with a username, in addition to the email.
kineticfocusover 11 years ago
I count five failed attempts within two days (190.39.254.6, 201.209.39.192, 85.152.192.118 ,186.88.197.41, 190.200.20.207). Good to know the password -that I almost manage to forget- is strong enough.
notwedtmover 11 years ago
I&#x27;m seeing similar failed attempts in my logs as well.
alexchamberlainover 11 years ago
If anyone from GitHub is reading, it would be cool if the failed IP addresses had an approximate location appended to them.
评论 #6760531 未加载
nicolscover 11 years ago
Only have one failed login attempt, from Ecuador. Should i be offended ?
aniketpantover 11 years ago
Here are my logs from the last two days:<p>user.failed_login<p>actor_ip 186.93.156.104<p>created_at 2013-11-18 14:45:30<p>---<p>user.failed_login<p>actor_ip 180.183.84.109<p>created_at 2013-11-18 06:05:01<p>---<p>user.failed_login<p>actor_ip 41.79.65.109<p>created_at 2013-11-17 12:55:31<p>---<p>user.failed_login<p>actor_ip 186.93.79.118<p>created_at 2013-11-17 12:40:34
beaker52over 11 years ago
<p><pre><code> user.failed_login: Originated from 129.49.72.52 2 days ago</code></pre>
m4tthumphreyover 11 years ago
They should provide the password used to attempt to log in too.
评论 #6760599 未加载
评论 #6760366 未加载
daGrevisover 11 years ago
Someone from Venezuela tried to log in, but failed.
animexcomover 11 years ago
Care to elaborate?