| ▲ | evanelias 8 hours ago | |
My sense is that a lot of this activity isn't even legitimate use. As one example: my company has a GitHub app, and last night some bot added my app to 1700 repos. Then the bot immediately started rapid-firing commits which each affected hundreds of files, triggering a deluge of GitHub webhooks to my servers. The repo names all matched other GitHub apps, so my sense is this bot had added 1700 GitHub apps to 1700 repos, with that number rapidly increasing at the upper bound of whatever GitHub's rate limit is. My systems caught it quickly and auto-booted the bot, but the whole situation is ridiculous. | ||
| ▲ | digitalsushi 8 hours ago | parent [-] | |
there's this attack on youtube where people who dont want their real names known will autoblock comments with their real names; bots will spam comments with every word and note the ones that were not visible. kinda reminds me of it. not my most valuable contribution to forensics, admittedly. | ||