HomeSecurityBug in GitHub Extension Visual Studio 'puts' developer in!

Bug in GitHub Extension Visual Studio 'puts' developer in!

Bug in GitHub Extension for Visual Studio 'costs' developer $6,500!

Carlo van Wyk, a South African web developer, claims he lost $6,500 (£4,250) in just a few hours due to a flaw in Microsoft's Visual Studio IDE tool with code-sharing site GitHub that inadvertently exposed his sensitive data .

Bug in GitHub Extension Visual Studio 'puts' developer in!
Despite the fact that he immediately changed his AWS root password, revoked all his access keys, and created new ones, within a few hours the scammers had managed to sign him into AWS's Elastic Compute Cloud. After that, his AWS account was charged a bill of $6,484.99.

 

He was using the Git Hub Extension for Visual Studio 2015. However, an unknown bug in the extension, developed and maintained by GitHub itself, stored his code in a public Git Hub repository, instead of a private one, as he intended.

Once the error was reported, both companies immediately corrected.

According to the report published a few days ago, about ten minutes after publishing his code, he received a notification from Amazon Web Services warning him that account had been exposed. He had also included an AWS access key in the code he had committed to GitHub.

Despite the fact that he immediately changed his AWS root password, revoked all his access keys, and created new ones, within a few hours the scammers had managed to sign him into AWS's Elastic Compute Cloud.
After that, his AWS account was charged a bill of $6,484.99.

AWS did not comment. However, GitHub has apologized for the error in its code, which it considers “unforgivable.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS