diff --git a/2024/05/2024-05-20-root-me-3.md b/2024/05/2024-05-20-root-me-3.md new file mode 100644 index 000000000..6a8604ec9 --- /dev/null +++ b/2024/05/2024-05-20-root-me-3.md @@ -0,0 +1,83 @@ +Before disabling any content in relation to this takedown notice, GitHub +- contacted the owners of some or all of the affected repositories to give them an opportunity to [make changes](https://docs.github.com/en/github/site-policy/dmca-takedown-policy#a-how-does-this-actually-work). +- provided information on how to [submit a DMCA Counter Notice](https://docs.github.com/en/articles/guide-to-submitting-a-dmca-counter-notice). + +To learn about when and why GitHub may process some notices this way, please visit our [README](https://github.com/github/dmca/blob/master/README.md#anatomy-of-a-takedown-notice). + +--- + +**Are you the copyright holder or authorized to act on the copyright owner's behalf?** + +Yes, I am the copyright holder. + +**Are you submitting a revised DMCA notice after GitHub Trust & Safety requested you make changes to your original notice?** + +No + +**Does your claim involve content on GitHub or npm.js?** + +GitHub + +**Please describe the nature of your copyright ownership or authorization to act on the owner's behalf.** + +My name is [private] and I'm the the [private] of the foundation Root-Me. + +**Please provide a detailed description of the original copyrighted work that has allegedly been infringed. If possible, include a URL to where it is posted online.** + +https://www.root-me.org/ : The foundation Root-Me is publishing/maintaining the portal root-me.org which is dedicated to information security learning through practical exercises. All those materials are under copyright, our legal information that users have to accept are available there : + +https://www.root-me.org/?page=structure&inc=page-mentions_legales&lang=en + +It is clearly forbidden (and penalized) to post exercise solution publicly. All those solutions use statement, code, URL, code of our exercises. We already propose to publish solution on our platform. + +**What files should be taken down? Please provide URLs for each file, or if the entire repository, the repository’s URL.** + +As we do not consider publishing solution as a student work or a simple mention. We found out that the Github user 'tadokun468' have leaked Root-Me owned exercise: + +https://github.com/tadokun468/Task5-File_upload_vulnerabilities/tree/master/Write_up_Rootme_FileUpLoad +https://github.com/tadokun468/Task-7-Local-File-Inclusion?tab=readme-ov-file#ii-root-me-challenges +https://github.com/tadokun468/Task4/tree/master/Rootme +https://github.com/tadokun468/Task6-SQL_Injection-Write_Up_Rootme + +For example, you can find https://www.root-me.org/en/Challenges/Web-Server/HTTP-IP-restriction-bypass here: +https://github.com/tadokun468/Task4/blob/master/Rootme/Rootme.md . +Another example is https://www.root-me.org/en/Challenges/Web-Server/Directory-traversal where the leak is available here https://github.com/tadokun468/Task-7-Local-File-Inclusion?tab=readme-ov-file#ii-root-me-challenges . +If you take a look at the repositories, you will understand that they without exception contains Root-Me foundation properties that need to be deleted or at least made private. + +According to your DMCA reporting guide. + +**Do you claim to have any technological measures in place to control access to your copyrighted content? Please see our Complaints about Anti-Circumvention Technology if you are unsure.** + +No + +**Have you searched for any forks of the allegedly infringing files or repositories? Each fork is a distinct repository and must be identified separately if you believe it is infringing and wish to have it taken down.** + +Yes and no forks exists + +**Is the work licensed under an open source license?** + +No + +**What would be the best solution for the alleged infringement?** + +Reported content must be removed + +**Do you have the alleged infringer’s contact information? If so, please provide it.** + +No + +**I have a good faith belief that use of the copyrighted materials described above on the infringing web pages is not authorized by the copyright owner, or its agent, or the law.** + +**I have taken fair use into consideration.** + +**I swear, under penalty of perjury, that the information in this notification is accurate and that I am the copyright owner, or am authorized to act on behalf of the owner, of an exclusive right that is allegedly infringed.** + +**I have read and understand GitHub's Guide to Submitting a DMCA Takedown Notice.** + +**So that we can get back to you, please provide either your telephone number or physical address.** + +ROOT-ME PRO [private] + +**Please type your full legal name below to sign this request.** + +[private]