Collected research
Breaking GitHub Private Pages for $35k
A CRLF injection in the page_id parameter of GitHub Pages private-page authentication, made exploitable by a null byte that stops integer parsing, yields script execution on the pages domain. Case variation bypasses the host-only cookie prefix to fixate the nonce, and a response cache keyed only on the integer page_id makes the payload persist for other users.
Record
- Researcher
- @NotDeGhost
- Published by
- robertchen.cc
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @NotDeGhost, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .