GitHub vulnerability?

Want to chit chat about anything, do it here ... posting here won't increase your post count (or shouldn't!). Please do not post any "phpBB" specific topics here unless they do not fit into the category above. Do not post bug reports, feature or support requests!
Forum rules
Please do not post any "phpBB" specific topics here unless they do not fit into the category above.

Do not post bug reports, feature or support requests! No really... Do not post bug reports, feature or support requests! Doing so will make Bertie a very sad bear indeed. :(
Post Reply
User avatar
DarkBeing
Registered User
Posts: 83
Joined: Sun Jul 19, 2009 2:32 pm
Location: Currently Estonia
Contact:

GitHub vulnerability?

Post by DarkBeing »

I am sure you have already read about this -> User Hacks GitHub to Showcase Vulnerability . Is there any concern, that phpbb code has to be checked, since it is hosted on Github as far as I understand?

User avatar
callumacrae
Former Team Member
Posts: 1046
Joined: Tue Apr 27, 2010 9:37 am
Location: England
Contact:

Re: GitHub vulnerability?

Post by callumacrae »

phpBB hasn't been affected. He pushed to the ruby branch because it was a bug in ruby (although they say that it isn't). He raised the issue a few days before, but it was ignored, so he demonstrated it.

GitHub fixed it quickly, though :-)
Made by developers, for developers!
My blog

User avatar
DarkBeing
Registered User
Posts: 83
Joined: Sun Jul 19, 2009 2:32 pm
Location: Currently Estonia
Contact:

Re: GitHub vulnerability?

Post by DarkBeing »

Yeah they fixed it, but only after he had to demonstrate it. The question which came to my mind is, if anyone else beside him knew about the bug and took advantage of it. From the conversation he had with the staff it appeared they did not take him seriously in the sense of "its a feature not a bug". Well, as long as everything is fine with the phpbb repositories, I am fine :D

User avatar
MichaelC
Development Team
Development Team
Posts: 889
Joined: Thu Jan 28, 2010 6:29 pm

Re: GitHub vulnerability?

Post by MichaelC »

It would be noticable if someone had pushed who doesn't normally have push permission as commit emails go out and it would show in commit logs. :)
Formerly known as Unknown Bliss
psoTFX wrote: I went with Olympus because as I said to the teams ... "It's been one hell of a hill to climb"
No unsolicited PMs please except for quotes.

igorw
Registered User
Posts: 500
Joined: Thu Jan 04, 2007 11:47 pm

Re: GitHub vulnerability?

Post by igorw »

He pushed to the ruby branch because it was a bug in ruby (although they say that it isn't).
Rails, and I don't see anyone denying it.

User avatar
callumacrae
Former Team Member
Posts: 1046
Joined: Tue Apr 27, 2010 9:37 am
Location: England
Contact:

Re: GitHub vulnerability?

Post by callumacrae »

igorw wrote:Rails, and I don't see anyone denying it.
Uh, that one.

They denied it - he made a bug report a few days previously, where he said that every major rails application he had tested was affected. They blamed it on the applications.
Made by developers, for developers!
My blog

Oleg
Posts: 1150
Joined: Tue Feb 23, 2010 2:38 am
Contact:

Re: GitHub vulnerability?

Post by Oleg »

If anyone changed any code in phpbb's repository we would know as pushes would fail with a non-fast-forward. So far this has not happened.

User avatar
callumacrae
Former Team Member
Posts: 1046
Joined: Tue Apr 27, 2010 9:37 am
Location: England
Contact:

Re: GitHub vulnerability?

Post by callumacrae »

That and we'd all have Recieved an email… :-D
Made by developers, for developers!
My blog

User avatar
MichaelC
Development Team
Development Team
Posts: 889
Joined: Thu Jan 28, 2010 6:29 pm

Re: GitHub vulnerability?

Post by MichaelC »

callumacrae wrote:That and we'd all have Recieved an email… :-D
Only for new commits,, not if someone rebased and forced pushed.
Formerly known as Unknown Bliss
psoTFX wrote: I went with Olympus because as I said to the teams ... "It's been one hell of a hill to climb"
No unsolicited PMs please except for quotes.

Post Reply