Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

fwiw, I tested this out as well by clicking open issue and uploading a file and then not actually submitting the issue. the file is still accessible 2 days later.

so it doesn't appear to be fixed. :-|



Just want to point out that GitHub removing the asset after 15 minutes is actually worse than leaving it. The least appetizing aspect of this for adversaries is that your payload is now forever available to anyone with the logs. If it were adversary’s choice (submit the issue and it stays, only draft the issue and it gets wiped, good riddance, a phenomenal c2 stager indeed!)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: