Content
@
https://warpcast.com/~/channel/orbiter
0 reply
0 recast
0 reaction
Justin Hunter
@polluterofminds
Big thanks to @cassie for identifying a potential vulnerability in Orbiter’s code that I didn’t even know was a thing! Open source for the win! Should be all patched now. If anyone finds anything, please reach out. We can’t pay bounties but we can pay in shoutout casts 😂
1 reply
1 recast
11 reactions
Joshua Hyde (he/him)
@jrh3k5.eth
What's the retrospective on the issue, out of curiosity?
1 reply
0 recast
2 reactions
Justin Hunter
@polluterofminds
It was a timing vulnerability where an attacker could guess the admin token for our nginx and analytics servers by guessing each character in the token and checking the time it takes for the request to fail to determine if a character in a specific position was right.
1 reply
0 recast
2 reactions
Joshua Hyde (he/him)
@jrh3k5.eth
Ahh, timing attacks. They're truly timeless.
0 reply
0 recast
3 reactions