GitHub vulnerability?
Forum rules
Please do not post any "phpBB" specific topics here unless they do not fit into the category above.
Do not post bug reports, feature or support requests! No really... Do not post bug reports, feature or support requests! Doing so will make Bertie a very sad bear indeed. :(
Please do not post any "phpBB" specific topics here unless they do not fit into the category above.
Do not post bug reports, feature or support requests! No really... Do not post bug reports, feature or support requests! Doing so will make Bertie a very sad bear indeed. :(
- DarkBeing
- Registered User
- Posts: 83
- Joined: Sun Jul 19, 2009 2:32 pm
- Location: Currently Estonia
- Contact:
GitHub vulnerability?
I am sure you have already read about this -> User Hacks GitHub to Showcase Vulnerability . Is there any concern, that phpbb code has to be checked, since it is hosted on Github as far as I understand?
- callumacrae
- Former Team Member
- Posts: 1046
- Joined: Tue Apr 27, 2010 9:37 am
- Location: England
- Contact:
Re: GitHub vulnerability?
phpBB hasn't been affected. He pushed to the ruby branch because it was a bug in ruby (although they say that it isn't). He raised the issue a few days before, but it was ignored, so he demonstrated it.
GitHub fixed it quickly, though
GitHub fixed it quickly, though
- DarkBeing
- Registered User
- Posts: 83
- Joined: Sun Jul 19, 2009 2:32 pm
- Location: Currently Estonia
- Contact:
Re: GitHub vulnerability?
Yeah they fixed it, but only after he had to demonstrate it. The question which came to my mind is, if anyone else beside him knew about the bug and took advantage of it. From the conversation he had with the staff it appeared they did not take him seriously in the sense of "its a feature not a bug". Well, as long as everything is fine with the phpbb repositories, I am fine 
Re: GitHub vulnerability?
It would be noticable if someone had pushed who doesn't normally have push permission as commit emails go out and it would show in commit logs. 
Formerly known as Unknown Bliss
No unsolicited PMs please except for quotes.psoTFX wrote: I went with Olympus because as I said to the teams ... "It's been one hell of a hill to climb"
Re: GitHub vulnerability?
Rails, and I don't see anyone denying it.He pushed to the ruby branch because it was a bug in ruby (although they say that it isn't).
- callumacrae
- Former Team Member
- Posts: 1046
- Joined: Tue Apr 27, 2010 9:37 am
- Location: England
- Contact:
Re: GitHub vulnerability?
Uh, that one.igorw wrote:Rails, and I don't see anyone denying it.
They denied it - he made a bug report a few days previously, where he said that every major rails application he had tested was affected. They blamed it on the applications.
Re: GitHub vulnerability?
If anyone changed any code in phpbb's repository we would know as pushes would fail with a non-fast-forward. So far this has not happened.
- callumacrae
- Former Team Member
- Posts: 1046
- Joined: Tue Apr 27, 2010 9:37 am
- Location: England
- Contact:
Re: GitHub vulnerability?
That and we'd all have Recieved an email… 
Re: GitHub vulnerability?
Only for new commits,, not if someone rebased and forced pushed.callumacrae wrote:That and we'd all have Recieved an email…
Formerly known as Unknown Bliss
No unsolicited PMs please except for quotes.psoTFX wrote: I went with Olympus because as I said to the teams ... "It's been one hell of a hill to climb"