GitHub apparently doesn't care about account security and wants user's accounts hacked and also organization's and individual's Intellectual Property stolen #159576
Replies: 10 comments 10 replies
-
|
💬 Your Product Feedback Has Been Submitted 🎉 Thank you for taking the time to share your insights with us! Your feedback is invaluable as we build a better GitHub experience for all our users. Here's what you can expect moving forward ⏩
Where to look to see what's shipping 👀
What you can do in the meantime 💻
As a member of the GitHub community, your participation is essential. While we can't promise that every suggestion will be implemented, we want to emphasize that your feedback is instrumental in guiding our decisions and priorities. Thank you once again for your contribution to making GitHub even better! We're grateful for your ongoing support and collaboration in shaping the future of our platform. ⭐ |
Beta Was this translation helpful? Give feedback.
-
|
3 weeks and not so much as a peep. |
Beta Was this translation helpful? Give feedback.
-
|
When looking at the IP's Censys overview https://search.censys.io/hosts/43.128.62.24, it seems it's just someone self-hosting at their residential IP address and running a reverse proxy to GitHub. So I assume there is not much GitHub themselves can do about this, right? |
Beta Was this translation helpful? Give feedback.
-
|
I am having the same issue and the thing is when you search my company website that ip link shows up additional seem like a bot github account is trying to confuse focs trying to find my actual repo for my org |
Beta Was this translation helpful? Give feedback.
-
|
The browser suggests this link several times and I think GitHub should take action as it seems to be used to steal information. Also, when searching for the IP on the browser, the most visited page is the login page ( on Brave at least ) |
Beta Was this translation helpful? Give feedback.
-
|
What's the issue here? As long as you don't use that proxy, your information can't be stolen. GitHub should just add some JS that warns you on the login page if you're not going through the official site. |
Beta Was this translation helpful? Give feedback.
-
|
How did you find that URL, I doubt majority of people will stumble into it, and if they do, im sure they will see the URL and not use it |
Beta Was this translation helpful? Give feedback.
-
|
I don't completely agree but on some places it does it |
Beta Was this translation helpful? Give feedback.
-
|
I found that IP on the first page of some Google results. That is another problem. |
Beta Was this translation helpful? Give feedback.
-
|
It appears that they fixed the leak (nearly a year later). I am closing this discussion now.
|
Beta Was this translation helpful? Give feedback.

Uh oh!
There was an error while loading. Please reload this page.
-
Select Topic Area
Product Feedback
Body
Description:
I have discovered a critical security vulnerability on GitHub.com that requires immediate action. This is the only place I have found to contact GitHub in regards to this issue.
I have discovered that the entirety of GitHub.com is available over http (unsecured) at the following IP address:
http://43.128.62.24:91/Theaxiom
This must be rectified immediately.
My original report of this issue was here: https://support.github.com/ticket/personal/0/3398324
Steps To Reproduce:
(Add details for how we can reproduce the issue)
1.Go to the following unprotected URL: http://43.128.62.24:91/Theaxiom
1.You will see my GitHub profile
Impact
The hacker can perform MITM attacks, as well as view/access personal and confidential information, such as passwords.
I reported this issue both to GitHub support and through their hacker bounty program and was essentially dismissed. See attached screenshots.
Beta Was this translation helpful? Give feedback.
All reactions