The Insidexpress
  • Business
  • Lifestyle
    • Fashion
    • Beauty
    • Home Decor
    • Home
    • Interior Design
    • Foods & Culinary
    • Dating & Relationships
    • Health
    • Pets & Animals
    • Spirituality
    • Sports & Athletics
    • Travel
  • Entertainment
    • Celebrities
    • Gaming
    • Movies
    • Music
    • TV
  • Financial
    • Loans
    • Insurance
    • Stocks
  • Industrial
    • Auto & Motor
    • Career
    • Education
    • CBD
    • Construction
    • Real Estate
    • eCommerce
    • Legal
    • Essay Writing
    • Gambling
    • Vaping
  • Technology
    • Digital Marketing
    • SEO
    • Cryptocurrency
    • Software
    • Metaverse
    • NFT
    • Web Design
    • WordPress
  • News
    • India
    • Basketball
    • Golf
    • Horse Racing
  • Business
  • Lifestyle
    • Fashion
    • Beauty
    • Home Decor
    • Home
    • Interior Design
    • Foods & Culinary
    • Dating & Relationships
    • Health
    • Pets & Animals
    • Spirituality
    • Sports & Athletics
    • Travel
  • Entertainment
    • Celebrities
    • Gaming
    • Movies
    • Music
    • TV
  • Financial
    • Loans
    • Insurance
    • Stocks
  • Industrial
    • Auto & Motor
    • Career
    • Education
    • CBD
    • Construction
    • Real Estate
    • eCommerce
    • Legal
    • Essay Writing
    • Gambling
    • Vaping
  • Technology
    • Digital Marketing
    • SEO
    • Cryptocurrency
    • Software
    • Metaverse
    • NFT
    • Web Design
    • WordPress
  • News
    • India
    • Basketball
    • Golf
    • Horse Racing
The Insidexpress is a centralized magazine for Lifestyle, Fashion, Beauty, DIY, Interior Design, Health, Relationships, Travel, HowTo & more.
The Insidexpress
  • Business
  • Lifestyle
    • Fashion
    • Beauty
    • Home Decor
    • Home
    • Interior Design
    • Foods & Culinary
    • Dating & Relationships
    • Health
    • Pets & Animals
    • Spirituality
    • Sports & Athletics
    • Travel
  • Entertainment
    • Celebrities
    • Gaming
    • Movies
    • Music
    • TV
  • Financial
    • Loans
    • Insurance
    • Stocks
  • Industrial
    • Auto & Motor
    • Career
    • Education
    • CBD
    • Construction
    • Real Estate
    • eCommerce
    • Legal
    • Essay Writing
    • Gambling
    • Vaping
  • Technology
    • Digital Marketing
    • SEO
    • Cryptocurrency
    • Software
    • Metaverse
    • NFT
    • Web Design
    • WordPress
  • News
    • India
    • Basketball
    • Golf
    • Horse Racing
  • Technology

Hacker Attains Admin Control of Sourcegraph, Granting Masses Free Access

  • September 6, 2023
  • 2 minute read
Total
0
Shares
0
0
0
0
0
0
0

Getty Images

An unknown hacker gained administrative control of Sourcegraph, an AI-driven service used by developers at Uber, Reddit, Dropbox, and other companies, and used it to provide free access to resources that normally would have required payment.

In the process, the hacker(s) may have accessed personal information belonging to Sourcegraph users, Diego Comas, Sourcegraph’s head of security, said in a post on Wednesday. For paid users, the information exposed included license keys and the names and email addresses of license key holders. For non-paying users, it was limited to email addresses associated with their accounts. Private code, emails, passwords, usernames, or other personal information were inaccessible.

Free-for-all

The hacker gained administrative access by obtaining an authentication key a Sourcegraph developer accidentally included in a code published to a public Sourcegraph instance hosted on Sourcegraph.com. After creating a normal user Sourcegraph account, the hacker used the token to elevate the account privileges to those of an administrator. The access token appeared in a pull request posted on July 14, the user account was created on August 28, and the elevation to admin occurred on August 30.

“The malicious user, or someone connected to them, created a proxy app allowing users to directly call Sourcegraph’s APIs and leverage the underlying LLM [large language model],” Comas wrote. “Users were instructed to create free Sourcegraph.com accounts, generate access tokens, and then request the malicious user to greatly increase their rate limit. On August 30 (2023-08-30 13:25:54 UTC), the Sourcegraph security team identified the malicious site-admin user, revoked their access, and kicked off an internal investigation for both mitigation and next steps.”

Advertisement

The resource free-for-all generated a spike in calls to Sourcegraph programming interfaces, which are normally rate-limited for free accounts.

A graph showing API usage from July 31 to August 29 with a major spike at the end.

Enlarge / A graph showing API usage from July 31 to August 29 with a major spike at the end.

Sourcegraph

“The promise of free access to Sourcegraph API prompted many to create accounts and start using the proxy app,” Comas wrote. “The app and instructions on how to use it quickly made its way across the web, generating close to 2 million views. As more users discovered the proxy app, they created free Sourcegraph.com accounts, adding their access tokens, and accessing Sourcegraph APIs illegitimately.”

Sourcegraph personnel eventually identified the surge in activity as “isolated and inorganic” and began investigating the cause. Comas said the company’s automated code analysis and other internal control systems “failed to catch the access token being committed to the repository.” Comas didn’t elaborate.

The token gave users the ability to view, modify, or copy the exposed data, but Comas said the investigation didn’t conclude if that actually happened. While most data was available for all paid and community users, the number of license keys exposed was limited to 20.

The inadvertent posting by developers of private credentials in publicly available code has been a problem plaguing online companies for more than a decade. These credentials can include private encryption keys, passwords, and authentication tokens. In the age of publicly accessible code repositories like GitHub, credentials should never be included in commits. Instead, they should be stored only on restricted servers.

Publisher

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Share 0
Share 0
Share 0
Share 0
Related Topics
  • access
  • Admin
  • Attains
  • Control
  • Free
  • Granting
  • hacker
  • Masses
  • Sourcegraph
The Insidexpress

You May Also Like
3 iOS 0-days, Cellular Network Compromise, and HTTP Used to Infect an iPhone
View Article
  • 3 min
  • Technology

3 iOS 0-days, Cellular Network Compromise, and HTTP Used to Infect an iPhone

  • September 23, 2023
View Article
  • 5 min
  • Technology

Surprising Federal Action Sparks Speculation of Interest Rate Increase

  • September 22, 2023
View Article
  • 7 min
  • Technology

Retiring Abroad: Choosing the Top International Retirement Destinations

  • September 22, 2023
View Article
  • 5 min
  • Technology

Tragedy Strikes in the Realm of Google Search

  • September 22, 2023
View Article
  • 8 min
  • Technology

10 EdTech Tools Enhancing the Digital Classroom

  • September 22, 2023
View Article
  • 4 min
  • Technology

Unlocking the Power of Financial Data: Enhancing Decision-Making through Data Annotation

  • September 22, 2023
View Article
  • 4 min
  • Technology

Unleashing Smart Contracts: Unlocking Business Breakthroughs

  • September 22, 2023
View Article
  • 5 min
  • Technology

Choose the Best Internet Service Provider for Your Business

  • September 22, 2023
    • Celebrities
    Royal Spending Soars to £107.5 Million with King Charles’ Cost-Saving Measures on Heating
    • Celebrities
    Colleen Ballinger Refutes Allegations of ‘Grooming’ Fans: Get All the Details
    • Celebrities
    Harry and Meghan Return Frogmore Cottage Keys After Royal Eviction Notice
    • Celebrities
    Kim Zolciak and Kroy Biermann’s Split and Custody Battle: Essential Information
    • Celebrities
    Ex-Glamour Model Melinda Messenger: Young Lads Seek My Attention Despite Age Gap
    • Celebrities
    Pete Davidson Enters Rehab Amid Mental Health Struggles, Reports Suggest
    • Celebrities
    The Secret Signals Princess Kate Sends with Her Outfits – Have You Spotted the Latest?
    • Celebrities
    Madonna Hospitalized Due to Severe Bacterial Infection
    • Celebrities
    Where can you find Frogmore Cottage, and is it still the current residence of Prince Harry and Meghan Markle?
    • Celebrities
    Pregnant Rihanna and ASAP Rocky Discuss Marital Plans: Reports
Featured Articles
  • Navigating the New Era of Customer Expectations: A Comprehensive Guide
    • 2 min
  • Navigating Email Marketing Regulations: A Comprehensive Guide to CAN-SPAM, GDPR, and More
    • 3 min
  • Translate Your Passion Into Your Purpose: A Step-by-Step Guide
    • 2 min
About Insidexpress

The Insidexpress is a centralized magazine for Business, Lifestyle, Fashion, Beauty, Entertainment, Culture, Living, Travel, Health, How-To, Technology, World News & more.

Things you might like
  • Although the owner of gambling sites is not on gamstop UK www.newonline-casinos.co.uk, his sites are successful and attract players. They have many slot machines and live sections; you can enjoy bonuses, especially free spins for new and popular slot online
  • List of non uk casinos accepting uk players newukcasino.uk
  • Best bonuses at european casinos that accept uk players with big wins
  • Visit Best CSGO Gambling to gather the latest gambling guides.
  • We have the best-reviewed crypto casinos at CryptoCasinos.com
Recent Posts
  • Pochettino’s Advice to Chelsea Star for Achieving Vinicius Jr’s Level amidst Potential Ban in Only Five Games 1
    Pochettino’s Advice to Chelsea Star for Achieving Vinicius Jr’s Level amidst Potential Ban in Only Five Games
    • 23.09.23
    • 2 min
  • 3 iOS 0-days, Cellular Network Compromise, and HTTP Used to Infect an iPhone 2
    3 iOS 0-days, Cellular Network Compromise, and HTTP Used to Infect an iPhone
    • 23.09.23
    • 3 min
  • Russell Brand speaks out after facing sexual assault accusations 3
    Russell Brand speaks out after facing sexual assault accusations
    • 23.09.23
    • 1 min
  • Reasons to Watch an Exceptional Korean Film 4
    Reasons to Watch an Exceptional Korean Film
    • 23.09.23
    • 4 min
The Insidexpress
  • Home
  • Contact Us

Input your search keywords and press Enter.