Hacker Newsnew | past | comments | ask | show | jobs | submitlogin



I really wish they would post what the attacker wants removed so we could mirror it, post it, etc. The streisand effect is a good response to things like this I think.


It appears that the first attack was targeted at https://github.com/cn-nytimes/ and https://github.com/greatfire/ [1]. Accessing these two pages still responds with `alert("WARNING: malicious javascript detected on this domain")` which is supposed to be executed on the (innocent) client's browser.

[1] https://news.ycombinator.com/item?id=9275381


You can access those pages by removing the final slash.


I think among the sites is the GreatFire repo: https://github.com/greatfire




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: