Feeds

Huge horde of droids whacks code box GitHub in password-guess attack

That's an awful lot of angry SVN users, in there

Internet Security Threat Report 2014

Miscreants have fired up a large army of remote-controlled computers to get around GitHub's login rate-limiting policies, designed to thwart attempts to brute-force guess the passwords for its users' accounts.

The bots, most likely unwitting PCs compromised by malware, have attacked the online source-code repository from "nearly 40,000 unique IP addresses", each trying to crack programmers' passwords, the company said this week.

"These addresses were used to slowly brute force weak passwords or passwords used on multiple sites. We are working on additional rate-limiting measures to address this," the website's team wrote.

While GitHub tries to develop new tech, it has rolled out a blocklist of commonly used weak passwords that people can no longer use on the service.

It has also reacted proactively "out of an abundance of caution," and has reset some user accounts' login credentials "even if a strong password was being used. Activity on these accounts showed logins from IP addresses involved in this incident."

As usual, the company recommended users consider enable two-factor authentication to their accounts to provide another line of defense against nefarious hacker probes.

GitHub is a popular target of hackers thanks to the vast piles of source code and suchlike material stored on it, some of which are held in private repositories. It has been a repeated victim of distributed denial-of-service attacks, and fell offline in early October after being hit by a huge multi-day attack.

It strikes us that GitHub's recent bout of probing may stem from crackers using the 38 million user details that were sucked out of Adobe recently to check for duplicate logins on other sites. Never use the same password and username combination on other sites, no matter how fringe. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Euro Parliament VOTES to BREAK UP GOOGLE. Er, OK then
It CANNA do it, captain.They DON'T have the POWER!
Download alert: Nearly ALL top 100 Android, iOS paid apps hacked
Attack of the Clones? Yeah, but much, much scarier – report
NSA SOURCE CODE LEAK: Information slurp tools to appear online
Now you can run your own intelligence agency
Post-Microsoft, post-PC programming: The portable REVOLUTION
Code jockeys: count up and grab your fabulous tablets
Twitter App Graph exposes smartphone spyware feature
You don't want everyone to compile app lists from your fondleware? BAD LUCK
Microsoft adds video offering to Office 365. Oh NOES, you'll need Adobe Flash
Lovely presentations... but not on your Flash-hating mobe
prev story

Whitepapers

Seattle children’s accelerates Citrix login times by 500% with cross-tier insight
Seattle Children’s is a leading research hospital with a large and growing Citrix XenDesktop deployment. See how they used ExtraHop to accelerate launch times.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Website security in corporate America
Find out how you rank among other IT managers testing your website's vulnerabilities.