|
|
|
|
|
by minxomat
2169 days ago
|
|
Another vector is takeover requests via their name squatting policy (that's how I got my username). But those requests shouldn't be approved unless the old account really is inactive. Might have been approved by mistake. Another vector is the as of yet unfixed GitHub "ghost" bug, which I discovered and detailed here: https://github.com/git-rest/spooky Note how you can read that repo, but the account https://github.com/git-rest doesn't exist. |
|
edit: the ghost repo is cool trick. Is there a writeup anywhere?