论文标题

GITHUB数据曝光并使用GraphQL安全设计缺陷访问阻止数据

Github Data Exposure and Accessing Blocked Data using the GraphQL Security Design Flaw

论文作者

Yazdipour, Shahriar

论文摘要

进行了这项研究的研究是为了说明如何使用GraphQl在GitHub中轻松获取数据访问残疾或阻塞的存储库。在某些情况下,您可能会失去对GitHub存储库的访问权限;当您使用GitHub服务的付费版本并且不支付每月付款或其他情况时,当您使用美国制裁清单中的github时。拥有不安全的存储库中使用恶意用法也可以将您的存储库放在Github黑名单中。在所有这些情况下,GitHub都会阻止和禁用您的存储库,您将无法访问您的文件,代码和项目资产。在这里,我们将讨论道德黑客如何使用GraphQL功能访问所有这些阻止数据的过程。

This research study was conducted to illustrate how it is easily possible to get data access to disabled or blocked repositories in Github using GraphQL. There are situations in which you can lose access to your Github repositories; When you use the paid version of Github services and do not pay the monthly payment or another situation is that when you use Github from the countries in the United States sanction list. Having an insecure repository with malicious usages can also put your repository in Github blacklist. In all of these situations, Github will block and disable your repository and you will lose access to your files, codes and project assets. Here, we will discuss the procedure of how an Ethical Hacker can gain access to all those blocked data with GraphQL functionality.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源