diff --git a/2024/04/2024-04-05-root-me.md b/2024/04/2024-04-05-root-me.md new file mode 100644 index 000000000..ec0388d56 --- /dev/null +++ b/2024/04/2024-04-05-root-me.md @@ -0,0 +1,83 @@ +Before disabling any content in relation to this takedown notice, GitHub +- contacted the owners of some or all of the affected repositories to give them an opportunity to [make changes](https://docs.github.com/en/github/site-policy/dmca-takedown-policy#a-how-does-this-actually-work). +- provided information on how to [submit a DMCA Counter Notice](https://docs.github.com/en/articles/guide-to-submitting-a-dmca-counter-notice). + +To learn about when and why GitHub may process some notices this way, please visit our [README](https://github.com/github/dmca/blob/master/README.md#anatomy-of-a-takedown-notice). + +--- + +**Are you the copyright holder or authorized to act on the copyright owner's behalf?** + +Yes, I am the copyright holder. + +**Are you submitting a revised DMCA notice after GitHub Trust & Safety requested you make changes to your original notice?** + +Yes + +**Please provide the Zendesk ticket number of your previously submitted notice. Zendesk ticket numbers are 7 digit ID numbers located in the subject line or body of your confirmation email.** + +2690035 + +**Does your claim involve content on GitHub or npm.js?** + +GitHub + +**Please describe the nature of your copyright ownership or authorization to act on the owner's behalf.** + +My name is [private] and I'm the the [private] of the foundation Root-Me. + +**Please provide a detailed description of the original copyrighted work that has allegedly been infringed. If possible, include a URL to where it is posted online.** + +https://www.root-me.org/ : The foundation Root-Me is publishing/maintaining the portal root-me.org which is dedicated to information security learning through practical exercises. All those materials are under copyright, our legal information that users have to accept are available there : + +https://www.root-me.org/?page=structure&inc=page-mentions_legales&lang=en + +It is clearly forbidden (and penalized) to post exercise solution publicly. All those solutions use statement, code, URL, code of our exercises. We already propose to publish solution on our platform. + +**What files should be taken down? Please provide URLs for each file, or if the entire repository, the repository’s URL.** + +As we do not consider publishing solution as a student work or a simple mention. We found out that the Github user RomaniukVadim have leaked Root-Me owned exercise: + +https://github.com/RomaniukVadim/wargaming-challenges/tree/master/RootMe + +For example, you can find https://www.root-me.org/en/Challenges/App-Script/sudo-weak-configuration here: https://github.com/RomaniukVadim/wargaming-challenges/blob/master/RootMe/app-script/Sudo-Weak_Configuration.txt . +Another example is https://www.root-me.org/en/Challenges/Web-Client/XSS-Stored-1 where the leak is available here https://github.com/RomaniukVadim/wargaming-challenges/blob/master/RootMe/web-client/xss-stored-1.txt . +If you take a look at the directory, you will understand that the entire 'RootMe' from the repository 'wargaming-challenges' without exception contains Root-Me foundation properties that must be deleted or at least made private. + +According to your DMCA reporting guide. + +**Do you claim to have any technological measures in place to control access to your copyrighted content? Please see our Complaints about Anti-Circumvention Technology if you are unsure.** + +No + +**Have you searched for any forks of the allegedly infringing files or repositories? Each fork is a distinct repository and must be identified separately if you believe it is infringing and wish to have it taken down.** + +Yes + +**Is the work licensed under an open source license?** + +No + +**What would be the best solution for the alleged infringement?** + +Repository can be made private + +**Do you have the alleged infringer’s contact information? If so, please provide it.** + +No + +**I have a good faith belief that use of the copyrighted materials described above on the infringing web pages is not authorized by the copyright owner, or its agent, or the law.** + +**I have taken fair use into consideration.** + +**I swear, under penalty of perjury, that the information in this notification is accurate and that I am the copyright owner, or am authorized to act on behalf of the owner, of an exclusive right that is allegedly infringed.** + +**I have read and understand GitHub's Guide to Submitting a DMCA Takedown Notice.** + +**So that we can get back to you, please provide either your telephone number or physical address.** + +ROOT-ME PRO - [private] + +**Please type your full legal name below to sign this request.** + +[private]