我github被攻破了

2013-11-20 11:19:43 +08:00
 tshwangq
半夜提示我多了一个ssh key。
我有私有repo 啊。。。
12349 次点击
所在节点    git
84 条回复
cloudqq
2013-11-20 11:25:40 +08:00
我表示怀疑,获取你私有项目有啥意义。
humiaozuzu
2013-11-20 11:27:22 +08:00
擦 我也是!
今天把所有能开启两步验证的全开了,密码全换不同的强密码了
被日了果然才知道不安全 LOL
Ray2EX
2013-11-20 11:27:28 +08:00
楼上太毒了
humiaozuzu
2013-11-20 11:28:10 +08:00
昨天 HN 上头条就是 Github is exp security issues,没想到今天自己就被日了。。。
tshwangq
2013-11-20 11:50:57 +08:00
怀疑什么?他无聊把我的项目公开呢,搞个什么10w个github repo bt。
我不好交代啊
LU35
2013-11-20 12:00:44 +08:00
半夜收到邮件提示密码被更改,还在想是什么情况。晚上就收到官方邮件,据说是受到adobe泄漏的影响。
c19
2013-11-20 12:26:30 +08:00
c19
2013-11-20 12:28:04 +08:00
https://github.com/settings/security
看看是不是被试密码了。。
xatest
2013-11-20 12:33:42 +08:00
@c19 看了一下,果然很多尝试失败的记录,幸好我是强密码~

a day ago user.failed_login: Originated from 186.14.6.207
a day ago user.failed_login: Originated from 190.79.142.40
2 days ago user.failed_login: Originated from 183.89.16.23
2 days ago user.failed_login: Originated from 190.72.6.251
2 days ago user.failed_login: Originated from 202.101.96.154
4 days ago user.failed_login: Originated from 200.84.65.94
4 days ago user.failed_login: Originated from 190.39.14.235
4 days ago user.failed_login: Originated from 93.61.60.10
4 days ago user.failed_login: Originated from 186.46.160.188
4 days ago user.failed_login: Originated from 201.210.49.168
4 days ago user.failed_login: Originated from 46.149.222.114
4 days ago user.failed_login: Originated from 201.211.85.139
4 days ago user.failed_login: Originated from 186.88.167.21
4 days ago user.failed_login: Originated from 186.92.91.46
4 days ago user.failed_login: Originated from 78.58.57.41
4 days ago user.failed_login: Originated from 186.95.160.168
4 days ago user.failed_login: Originated from 186.95.64.36
4 days ago user.failed_login: Originated from 182.253.48.86
4 days ago user.failed_login: Originated from 175.141.33.131
4 days ago user.failed_login: Originated from 197.210.255.150
4 days ago user.failed_login: Originated from 186.94.149.202
4 days ago user.failed_login: Originated from 190.207.170.157
4 days ago user.failed_login: Originated from 200.192.215.138
4 days ago user.failed_login: Originated from 190.207.0.10
4 days ago user.failed_login: Originated from 190.203.78.224
4 days ago user.failed_login: Originated from 82.79.66.19
4 days ago user.failed_login: Originated from 118.99.114.199
4 days ago user.failed_login: Originated from 186.94.246.28
FrankFang128
2013-11-20 12:53:13 +08:00
你们的密码是不是很弱
greenmoon55
2013-11-20 13:03:18 +08:00
two_factor_authentication.enabled:
a day ago user.failed_login: Originated from 190.36.202.117
a day ago user.failed_login: Originated from 114.32.114.10
a day ago user.failed_login: Originated from 78.46.250.85
2 days ago user.failed_login: Originated from 1.64.139.71
2 days ago user.failed_login: Originated from 186.95.46.139
2 days ago user.failed_login: Originated from 190.207.233.235
mlc880926
2013-11-20 13:04:12 +08:00
user.failed_login: Originated from 201.211.5.166
a day ago user.failed_login: Originated from 190.73.130.185
a day ago user.failed_login: Originated from 182.253.32.15
2 days ago user.failed_login: Originated from 41.46.80.107
2 days ago user.failed_login: Originated from 190.73.235.26
2 days ago user.failed_login: Originated from 190.79.222.225
我也有不少
suziewong
2013-11-20 13:05:41 +08:00
我也有,这个是什么情况呀
sophy
2013-11-20 13:06:43 +08:00
把两步验证打开啊
9hills
2013-11-20 13:09:02 +08:00
@suziewong 只要保证一站一密,然后强密码就没事

github本身没问题,是用户的密码有问题
thai9quohs6jae1C
2013-11-20 13:18:03 +08:00
能两步验证的都打开了的
dorentus
2013-11-20 13:24:15 +08:00
我这里只有两条,五小时前的 IP 是国外的,八天前的 IP 是阿里云的……

user.failed_login: Originated from 188.251.253.106 5 hours ago
user.failed_login: Originated from 115.29.148.201 8 days ago
ffts
2013-11-20 13:29:18 +08:00
我的也是诶...
还是改密码吧...
airyland
2013-11-20 13:30:43 +08:00
我也是!!
reorx
2013-11-20 13:38:44 +08:00
很明显这是想用 github 帐号从 ripple 搞钱的人干的

这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。

https://www.v2ex.com/t/89900

V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。

V2EX is a community of developers, designers and creative people.

© 2021 V2EX