phpBB

Development Discussion Board

phpBB's testing ground of bleeding edge code
Advanced search

GitHub vulnerability?

Want to chit chat about anything, do it here ... posting here won't increase your post count (or shouldn't!). Please do not post any "phpBB" specific topics here unless they do not fit into the category above. Do not post bug reports, feature or support requests!
Forum rules
Please do not post any "phpBB" specific topics here unless they do not fit into the category above.

Do not post bug reports, feature or support requests! No really... Do not post bug reports, feature or support requests! Doing so will make Bertie a very sad bear indeed. :(

GitHub vulnerability?

Postby DarkBeing » Tue Mar 06, 2012 10:24 am

I am sure you have already read about this -> User Hacks GitHub to Showcase Vulnerability . Is there any concern, that phpbb code has to be checked, since it is hosted on Github as far as I understand?
DarkBeing
Registered User
 
Posts: 48
Joined: Sun Jul 19, 2009 2:32 pm
Location: Currently Japan

Re: GitHub vulnerability?

Postby callumacrae » Tue Mar 06, 2012 12:06 pm

phpBB hasn't been affected. He pushed to the ruby branch because it was a bug in ruby (although they say that it isn't). He raised the issue a few days before, but it was ignored, so he demonstrated it.

GitHub fixed it quickly, though :-)
"In JavaScript, there is a beautiful, elegant, highly expressive language that is buried under a steaming pile of good intentions and blunders"
—Douglas Crockford

View my MOD, phpBB Mobile
User avatar
callumacrae
Website Team
Website Team
 
Posts: 883
Joined: Tue Apr 27, 2010 9:37 am
Location: England

Re: GitHub vulnerability?

Postby DarkBeing » Tue Mar 06, 2012 1:00 pm

Yeah they fixed it, but only after he had to demonstrate it. The question which came to my mind is, if anyone else beside him knew about the bug and took advantage of it. From the conversation he had with the staff it appeared they did not take him seriously in the sense of "its a feature not a bug". Well, as long as everything is fine with the phpbb repositories, I am fine :D
DarkBeing
Registered User
 
Posts: 48
Joined: Sun Jul 19, 2009 2:32 pm
Location: Currently Japan

Re: GitHub vulnerability?

Postby MichaelC » Tue Mar 06, 2012 4:32 pm

It would be noticable if someone had pushed who doesn't normally have push permission as commit emails go out and it would show in commit logs. :)
Unknown Bliss
psoTFX wrote:I went with Olympus because as I said to the teams ... "It's been one hell of a hill to climb"

No unsolicited PMs please except for quotes.
User avatar
MichaelC
Website Team
Website Team
 
Posts: 797
Joined: Thu Jan 28, 2010 6:29 pm

Re: GitHub vulnerability?

Postby igorw » Fri Mar 16, 2012 2:59 pm

He pushed to the ruby branch because it was a bug in ruby (although they say that it isn't).

Rails, and I don't see anyone denying it.
User avatar
igorw
Registered User
 
Posts: 500
Joined: Thu Jan 04, 2007 11:47 pm

Re: GitHub vulnerability?

Postby callumacrae » Fri Mar 16, 2012 5:07 pm

igorw wrote:Rails, and I don't see anyone denying it.

Uh, that one.

They denied it - he made a bug report a few days previously, where he said that every major rails application he had tested was affected. They blamed it on the applications.
"In JavaScript, there is a beautiful, elegant, highly expressive language that is buried under a steaming pile of good intentions and blunders"
—Douglas Crockford

View my MOD, phpBB Mobile
User avatar
callumacrae
Website Team
Website Team
 
Posts: 883
Joined: Tue Apr 27, 2010 9:37 am
Location: England

Re: GitHub vulnerability?

Postby Oleg » Mon Mar 19, 2012 5:48 am

If anyone changed any code in phpbb's repository we would know as pushes would fail with a non-fast-forward. So far this has not happened.
Oleg
3.1 Release Manager
3.1 Release Manager
 
Posts: 1150
Joined: Tue Feb 23, 2010 2:38 am

Re: GitHub vulnerability?

Postby callumacrae » Mon Mar 19, 2012 6:12 am

That and we'd all have Recieved an email… :-D
"In JavaScript, there is a beautiful, elegant, highly expressive language that is buried under a steaming pile of good intentions and blunders"
—Douglas Crockford

View my MOD, phpBB Mobile
User avatar
callumacrae
Website Team
Website Team
 
Posts: 883
Joined: Tue Apr 27, 2010 9:37 am
Location: England

Re: GitHub vulnerability?

Postby MichaelC » Mon Mar 19, 2012 12:47 pm

callumacrae wrote:That and we'd all have Recieved an email… :-D


Only for new commits,, not if someone rebased and forced pushed.
Unknown Bliss
psoTFX wrote:I went with Olympus because as I said to the teams ... "It's been one hell of a hill to climb"

No unsolicited PMs please except for quotes.
User avatar
MichaelC
Website Team
Website Team
 
Posts: 797
Joined: Thu Jan 28, 2010 6:29 pm


Return to Chit Chat

Who is online

Users browsing this forum: No registered users and 11 guests