TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

XSS vulnerability found in Github

69 点作者 Stuk超过 14 年前

5 条评论

pilif超过 14 年前
This might look really funny, but consider this: The javascript you are executing there runs on the github domain. So it can do whatever you can do by manually clicking.<p>The injected script could for example submit a new SSH public key for your account (doesn't require your password again). Or just be funny and delete repos. Or just upgrading your account to a bigger, more expensive plan.<p>Or they could get a list of your private repositories. Combine that with the upload of a new private key and you'll get free access to proprietary code of any account.<p>Aside of fixing the XSS issue, they really should ask for the password again when uploading a public key.
chrisbroadfoot超过 14 年前
Seems to be fixed now.<p>Quick work by the github guys, kudos.<p>For those who missed it, the title attribute inside commit messages in the file list wasn't HTML encoded.
评论 #2024421 未加载
mike-cardwell超过 14 年前
Didn't work for me. Then I remembered to tell noscript to enable js. Does anyone still need convincing that they should be using noscript?
评论 #2024409 未加载
评论 #2024376 未加载
评论 #2024249 未加载
评论 #2024250 未加载
评论 #2024273 未加载
Stuk超过 14 年前
Something @chrislloyd and I found in Github. Nothing too serious!
评论 #2024199 未加载
评论 #2024175 未加载
评论 #2024383 未加载
评论 #2024189 未加载
评论 #2024201 未加载
Garbage超过 14 年前
Not working for me. Is it fixed? I can see only JavaScript. IE8 on Windows XP.
评论 #2024347 未加载