TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Tell HN: Publicly editable GitHub wikis can be abused to distribute malware

1 点作者 xeeeeeeeeeeenu超过 2 年前
It&#x27;s only a matter of time until someone abuses a publicly editable wiki. For example, as someone noticed on Reddit[1], a link to Git for Windows on Vundle&#x27;s wiki was replaced with a link to malware:<p>https:&#x2F;&#x2F;github.com&#x2F;VundleVim&#x2F;Vundle.vim&#x2F;wiki&#x2F;Vundle-for-Windows&#x2F;_compare&#x2F;3aeb22ac39229af4312f2be1052ead184dd5b54d...aa3d293dd18ae1cb4f049c43b73b951651515863<p>In fact, most of the recent edits (made by many different accounts) were malicious:<p>https:&#x2F;&#x2F;github.com&#x2F;VundleVim&#x2F;Vundle.vim&#x2F;wiki&#x2F;Vundle-for-Windows&#x2F;_history<p>I recommend restricting editing in your GitHub wikis to collaborators only.<p>[1] - https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;vim&#x2F;comments&#x2F;zzcn10&#x2F;vimorg_autosave_vundle_plugin_windows_installer&#x2F;

暂无评论

暂无评论