Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The package cache proxy is usually used to fetch from the public repository (npm, rubygems, etc.) so I think it could be feasible to craft some package metadata to trick it into GETing unexpected things. PUT/POST could be possible via attempting to publish


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: