Github Data Exposure and Accessing Blocked Data using the GraphQL Security Design Flaw

05/27/2020
by   Shahriar Yazdipour, et al.
0

This research study was conducted to illustrate how it is easily possible to get data access to disabled or blocked repositories in Github using GraphQL. There are situations in which you can lose access to your Github repositories; When you use the paid version of Github services and do not pay the monthly payment or another situation is that when you use Github from the countries in the United States sanction list. Having an insecure repository with malicious usages can also put your repository in Github blacklist. In all of these situations, Github will block and disable your repository and you will lose access to your files, codes and project assets. Here, we will discuss the procedure of how an Ethical Hacker can gain access to all those blocked data with GraphQL functionality.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/20/2018

Categorizing the Content of GitHub README Files

README files play an essential role in shaping a developer's first impre...
research
08/14/2019

Large-Scale-Exploit of GitHub Repository Metadata and Preventive Measures

When working with Git, a popular version-control system, email addresses...
research
10/25/2021

Generating GitHub Repository Descriptions: A Comparison of Manual and Automated Approaches

Given the vast number of repositories hosted on GitHub, project discover...
research
06/26/2022

Repository-Level Prompt Generation for Large Language Models of Code

With the success of large language models (LLMs) of code and their use a...
research
02/25/2021

What's in a GitHub Repository? – A Software Documentation Perspective

Developers use and contribute to repositories on GitHub. Documentation p...
research
09/13/2023

OWL Reasoners still useable in 2023

In a systematic literature and software review over 100 OWL reasoners/sy...
research
10/02/2018

CINIC-10 is not ImageNet or CIFAR-10

In this brief technical report we introduce the CINIC-10 dataset as a pl...

Please sign up or login with your details

Forgot password? Click here to reset