Lemmy: Bestiverse
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
RSS BotMB to Lobste.rsEnglish · 11 hours ago

How I Scanned all of GitHub’s “Oops Commits” for Leaked Secrets worth $25k in Bug Bounties

trufflesecurity.com

external-link
message-square
0
fedilink
3
external-link

How I Scanned all of GitHub’s “Oops Commits” for Leaked Secrets worth $25k in Bug Bounties

trufflesecurity.com

RSS BotMB to Lobste.rsEnglish · 11 hours ago
message-square
0
fedilink
Guest Post: How I Scanned all of GitHub’s “Oops Commits” for Leaked Secrets ◆ Truffle Security Co.
trufflesecurity.com
external-link
GitHub Archive logs every public commit, even the ones developers try to delete. Force pushes often cover up mistakes like leaked credentials by rewriting Git history. GitHub keeps these dangling commits, from what we can tell, forever. In the archive, they show up as “zero-commit” PushEvents.

Comments

alert-triangle
You must log in or register to comment.

Lobste.rs

lobsters

Subscribe from Remote Instance

You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !lobsters@lemmy.bestiver.se
lock
Community locked: only moderators can create posts. You can still comment on posts.

RSS Feed of lobste.rs

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 31 users / day
  • 111 users / week
  • 316 users / month
  • 1.2K users / 6 months
  • 2 local subscribers
  • 206 subscribers
  • 6.12K Posts
  • 292 Comments
  • Modlog
  • mods:
  • patrick
  • RSS Bot
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org