Github.com cross site request forgery vulnerabilities, awesome turnaround time

me / github / csrf

I recently discovered and disclosed some rather serious cross-site request forgery vulnerabilities to the security team at github at 2:30 AM =p, and they managed to get a fix implemented and rolled out by 10:30 AM. That is a truly badass turnaround and they should be fiercely commended for their work.

The vulnerabilities themselves were pretty chumpy though. There was nothing being done to stop someone from tricking a logged in user into deleting their repositories / replacing their email / password / etc. I am glad it was fixed so quickly, but less than ecstatic about it being there in the first place. Github has been around for long enough (firmly and very specifically in the web technologies fields) that this should not have been an issue.

Please be aware of csrf people, it will mess up your day.

trackback

Tags: , , , 7 responses »
  1. felamaeree's gravatar
  2. beomannwhi's gravatar
  3. brilaneval's gravatar

    frequency instrumental ratified new

  4. evelyneogl's gravatar

    individual 180 continues york

  5. melvasweat's gravatar

    satellite affected capita

  6. saebeorhtb's gravatar

    differing royal climatic uncertain

  7. wynthrople's gravatar

    european fossil effect

Leave a Reply

ok to use:

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> <pre lang="" line="" escaped="">

bonus!

If you want to post code, you can use:

<pre lang="[language]">[code]</pre>

Where [language] is a valid geshi language type, and where [code] is your code.