logoalt Hacker News

halgeryesterday at 7:28 PM1 replyview on HN

Woah I wonder if they can tell if this has been exploited or not


Replies

semiquaveryesterday at 7:50 PM

My read is that this vulnerability is exploitable by an anonymous user. They absolutely have HTTP/gitprotocol logs that would indicate whether this was exploited but if it was, they won’t have logging about what actually got accessed and who did it, since the exploit was capable of standalone execution on the git servers, which would by definition be capable of evading any logging.