How I gained commit access to Homebrew in 30 minutes
In Summary : An OSSINT tool from Michael Henriksen called gitrob makes automating this search really easy. I ran it across the Homebrew ...
https://updatesinfosec.blogspot.com/2018/08/how-i-gained-commit-access-to-homebrew.html
In Summary :
kindly refer the following link as follow up :
https://ift.tt/2OR46t6
An OSSINT tool from Michael Henriksen called gitrob
makes automating this search really easy. I ran it across the Homebrew
organization, but ultimately didn’t come up with anything interesting.
Next, I took a look at previously disclosed issues on https://hackerone.com/Homebrew. From there, I found that Homebrew runs a Jenkins instance that’s (intentionally) publicly exposed at https://jenkins.brew.sh.
After
some digging, I noticed something interesting; builds in the “Homebrew
Bottles” project were making authenticated pushes to the [...]kindly refer the following link as follow up :
https://ift.tt/2OR46t6