Hacker gains admin control of Sourcegraph and gives free access to the masses

Hacker gains admin control of Sourcegraph and gives free access to the masses

Read in 4.4 mintues

WEBFITECH  | MAGAZINE | NEWS | CRYPTO & MARKET | LATINO |⛅WEATHER | 🟢LIVE |

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors


Getty Images

An unknown hacker gained administrative control of Sourcegraph, an AI-driven service used by developers at Uber, Reddit, Dropbox, and other companies, and used it to provide free access to resources that normally would have required payment.

In the process, the hacker(s) may have accessed personal information belonging to Sourcegraph users, Diego Comas, Sourcegraph’s head of security, said in a post on Wednesday. For paid users, the information exposed included license keys and the names and email addresses of license key holders. For non-paying users, it was limited to email addresses associated with their accounts. Private code, emails, passwords, usernames, or other personal information were inaccessible.

WEBFI Hosting Service for lifetime - Onetime Donation - LifeTime Hosting Service for a lifetime - Onetime Donation - Lifetime License Are you the owner of your domain? With your Donation to WEBFI.NET, you get a space on our servers under the WordPress format, with unlimited disk space, unlimited bandwidth, premium access to premium themes galleries and Premium WordPress Plugins, and unlimited HTTPS WildCard protocol. Immediate activation 24 hours after your donation is confirmed. Lifetime license - One-Time Donation. Donations are processed by PayPal and PayPal Guest so you don't need a PayPal account, you can safely use debit, credit, or gift cards. The concept is simple and runs in as little as 24 hours *ONETIME Donation *WordPress-PRO Platform. *Unlimited Disk Space*Unlimited Bandwidth *SSL Wildcard Certificate *99.5% UPTIME *WordPress Premium PRO All Access Platform, Themes, and Plugins *24Hrs activation time from any phone or computer via www.1877.link or @ctmmagazine DM 0r in our customer service board WEBFI is aimed at anyone who seeks to be informed and entertained or wants to publish their opinions and news in real time. This is an Open and Public website, your opinions and post can be seen at the front on the home page and directories. webfinet website ownership license for lifetime With your Donation to WEBFI.NET, you get a space on our servers under the WordPress format, with unlimited disk space, unlimited bandwidth, premium access to premium themes galleries and Premium WordPress Plugins, and unlimited HTTPS WildCard protocol. Immediate activation 24 hours after your donation is confirmed. Lifetime license - One-Time Donation. Donations are processed by PayPal and PayPal Guest so you don't need a PayPal account, you can safely use debit, credit, or gift cards. The concept is simple and runs in as little as 24 hours *ONETIME Donation *WordPress-PRO Platform. *Unlimited Disk Space*Unlimited Bandwidth *SSL Wildcard Certificate *99.5% UPTIME *WordPress Premium PRO All Access Platform, Themes, and Plugins *24Hrs activation time from any phone or computer via www.1877.link  or @ctmmagazine DM 0r in our customer service board Get your own space to host your website for a single donation that allows you to host your project for life without the need for recurring payments, you only pay for your domain annuities to your domain provider and that's it!
LIVE

Free-for-all

The hacker gained administrative access by obtaining an authentication key a Sourcegraph developer accidentally included in a code published to a public Sourcegraph instance hosted on Sourcegraph.com. After creating a normal user Sourcegraph account, the hacker used the token to elevate the account privileges to those of an administrator. The access token appeared in a pull request posted on July 14, the user account was created on August 28, and the elevation to admin occurred on August 30.

“The malicious user, or someone connected to them, created a proxy app allowing users to directly call Sourcegraph’s APIs and leverage the underlying LLM [large language model],” Comas wrote. “Users were instructed to create free Sourcegraph.com accounts, generate access tokens, and then request the malicious user to greatly increase their rate limit. On August 30 (2023-08-30 13:25:54 UTC), the Sourcegraph security team identified the malicious site-admin user, revoked their access, and kicked off an internal investigation for both mitigation and next steps.”

The resource free-for-all generated a spike in calls to Sourcegraph programming interfaces, which are normally rate-limited for free accounts.

A graph showing API usage from July 31 to August 29 with a major spike at the end.
Enlarge / A graph showing API usage from July 31 to August 29 with a major spike at the end.

Sourcegraph

“The promise of free access to Sourcegraph API prompted many to create accounts and start using the proxy app,” Comas wrote. “The app and instructions on how to use it quickly made its way across the web, generating close to 2 million views. As more users discovered the proxy app, they created free Sourcegraph.com accounts, adding their access tokens, and accessing Sourcegraph APIs illegitimately.”

Sourcegraph personnel eventually identified the surge in activity as “isolated and inorganic” and began investigating the cause. Comas said the company’s automated code analysis and other internal control systems “failed to catch the access token being committed to the repository.” Comas didn’t elaborate.

The token gave users the ability to view, modify, or copy the exposed data, but Comas said the investigation didn’t conclude if that actually happened. While most data was available for all paid and community users, the number of license keys exposed was limited to 20.

The inadvertent posting by developers of private credentials in publicly available code has been a problem plaguing online companies for more than a decade. These credentials can include private encryption keys, passwords, and authentication tokens. In the age of publicly accessible code repositories like GitHub, credentials should never be included in commits. Instead, they should be stored only on restricted servers.



Source link

WEBFI – WEBFI Unstoppable Private Websites – Ownership for lifetime. Live News Magazine Own a private website for life with WEBFI NET. Our private servers offer the best in security and performance, and our lifetime license means you'll never have to worry about renewing your hosting again. Plus, get unlimited access to our Live News Online Magazine, which features a brief look at national & global news from all points of view, plus entertainment, live weather radar, and streaming. No registration or download is required. Available in English and Spanish. WEBFINET Private Servers since 2018 Web Hosting lifetime license info via TEXT-WhatsApp. Former Ctm Magazine 2009 X-@ctmmagazine

🏠 | Tech | Live🟢 | Magazine | News | Crypto | Weather | 🇪🇸 | 🍿 | TermsPrivacy |

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors

Unstoppable Private Websites – Ownership for lifetime. Live News Magazine. Own a private website for life with WebFi. Our private servers offer the best in security and performance,and our lifetime license means you'll never have to worry about renewing your hosting again.

Get your own Webfi space to host your website for a single donation that allows you to host your project for life without the need for recurring payments, You only pay for your domain annuities to your domain provider and that's it! LEARN MORE

⚖News Balance🇺🇲

The WEBFI algorithm collects the active news on the Internet and temporarily exposes it on this platform, both in written and video format. WEBFI Network - News Balance Security, does not show advertising in its contents, does not redirect to other sites, and filters any graphic content evaluated as insecure, sensitive, or private. In this way, we ensure that all visitors are informed without distraction and safely. The opinions and content issued on this platform do not necessarily reflect the opinion, philosophy, or vision of WEBFINET. We strongly believe in freedom of speech.

🏠 | Tech | Live🟢 | Magazine | News | Crypto | Weather | 🇪🇸 | 🍿 | TermsPrivacy | HURRICANE WATCH 

WEBFI ⚖News Balance🇺🇲 is publishing 24/7/365, Our playlist⏯ compacts a fully balanced news program with a broad look at national USA and World politics, tech, weather, events, and entertainment news. No subscription, registration, or download is needed. Ad-Free. WEBFI Unstoppable Websites

 Since 2018 WEBFI

X


WEBFI – WEBFI Unstoppable Private Websites – Ownership for lifetime. Live News Magazine Own a private website for life with WEBFI NET. Our private servers offer the best in security and performance, and our lifetime license means you'll never have to worry about renewing your hosting again. Plus, get unlimited access to our Live News Online Magazine, which features a brief look at national & global news from all points of view, plus entertainment, live weather radar, and streaming. No registration or download is required. Available in English and Spanish. WEBFINET Private Servers since 2018 Web Hosting lifetime license info via TEXT-WhatsApp. Former Ctm Magazine 2009 X-@ctmmagazine
Contact us
error: WEBFI NETWORK website Protection and Privacy for Publishers. This content may not be copied.