Showing posts with label Github. Show all posts
Showing posts with label Github. Show all posts

Sunday, February 9, 2014

[Egor Homakov] How I hacked Github again

This is a story about 5 Low-Severity bugs I pulled together to create a simple but high severity exploit, giving me access to private repositories on Github.

These vulnerabilities were reported privately and fixed in timely fashion. Here is the "timeline" of my emails.

More detailed/alternative explanation.