Web Hack List

Collected research

How I hacked GitHub again

Egor Homakov: How I hacked Github again.

Chains five low-severity GitHub OAuth bugs: redirect_uri path traversal with slash-dot-dot, no redirect_uri check at the token endpoint, a Camo proxy bypass that leaks the code through the Referer, Gist exposing the access token in a cookie, and auto-approved scopes. The result is a script-less takeover with read and write access to private repositories.

Record

Document
Egor Homakov: How I hacked Github again.
Published by
homakov.blogspot.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of homakov.blogspot.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .