<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>trickeries! &#187; github</title>
	<atom:link href="http://trickeries.com/tag/github/feed/" rel="self" type="application/rss+xml" />
	<link>http://trickeries.com</link>
	<description>it's tricky to rock a style thats liked online</description>
	<lastBuildDate>Tue, 02 Mar 2010 06:01:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Github.com cross site request forgery vulnerabilities, awesome turnaround time</title>
		<link>http://trickeries.com/854/github.com-cross-site-request-forgery-vulnerabilities-awesome-turnaround-time/</link>
		<comments>http://trickeries.com/854/github.com-cross-site-request-forgery-vulnerabilities-awesome-turnaround-time/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 18:18:32 +0000</pubDate>
		<dc:creator>atom</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[CSRF]]></category>
		<category><![CDATA[github]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://trickeries.com/?p=854</guid>
		<description><![CDATA[


I recently discovered and disclosed some rather serious cross-site request forgery vulnerabilities to the security team at github at 2:30 AM =p, and they managed to get a fix implemented and rolled out by 10:30 AM.  That is a truly badass turnaround and they should be fiercely commended for their work.
The vulnerabilities themselves were [...]]]></description>
			<content:encoded><![CDATA[<p class="image">
<img src="http://trickeries.com/wp-content/uploads/2010/01/me-github-csrf.png" alt="me / github / csrf" title="me / github / csrf" width="434" height="286" />
</p>
<p>I recently discovered and disclosed some rather serious <a href="http://en.wikipedia.org/wiki/Cross_site_request_forgery">cross-site request forgery</a> vulnerabilities to the security team at <a href="http://github.com">github</a> at 2:30 AM =p, and they managed to get a fix implemented and rolled out by 10:30 AM.  <strong><em>That is a truly badass turnaround and they should be fiercely commended for their work</em></strong>.</p>
<p>The vulnerabilities themselves were pretty chumpy though.  There was <em>nothing</em> being done to stop someone from tricking a logged in user into deleting their repositories / replacing their email / password / etc.  I am glad it was fixed so quickly, but less than ecstatic about it being there in the first place.  Github has been around for long enough (firmly and very specifically in the web technologies fields) that this should not have been an issue.</p>
<p>Please be aware of <a href="http://en.wikipedia.org/wiki/Cross_site_request_forgery">csrf</a> people, it will mess up your day.</p>
]]></content:encoded>
			<wfw:commentRss>http://trickeries.com/854/github.com-cross-site-request-forgery-vulnerabilities-awesome-turnaround-time/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>
