Action Anomalies: A Hackers Guide To Github Actions - Elliot Ward

  Рет қаралды 155

DEFCON Switzerland

DEFCON Switzerland

Күн бұрын

Elliot Ward (Snyk)
In the DevOps era of frequent releases, CI tools such as Github actions are powerful platforms to
enable secure and rapid software releases, but what additional attack surface do these often privileged components come with? This talk covers a recent research project from Snyk Security Labs to understand Github actions in depth and how they can be attacked to leak cloud environment access tokens, arbitrary secrets and result in a full compromise of the repository. Security engineers,
pentesters and bug hunters alike will come away knowing the threat landscape for Githubs CI platform, and through case studies of high impact vulnerabilities we have uncovered, be equipped to exploit and secure Github actions.

Пікірлер
Incredible Dog Rescues Kittens from Bus - Inspiring Story #shorts
00:18
Fabiosa Best Lifehacks
Рет қаралды 39 МЛН
escape in roblox in real life
00:13
Kan Andrey
Рет қаралды 46 МЛН
OpenAI Releases GPT Strawberry 🍓 Intelligence Explosion!
21:21
Matthew Berman
Рет қаралды 175 М.
Automating Malware Development: A Red Teamer's Journey - Gian Demarmels
45:11
😱ЖИВОЙ Чехол на Айфон🤪
0:38
Demin's Lounge
Рет қаралды 427 М.
PlayStation 5 Pro Console - Reveal Trailer
1:05
PlayStation
Рет қаралды 2,2 МЛН
Я КУПИЛ СЕБЕ КЛАВИАТУРУ С ЭКРАНОМ
0:36
Что за спешка, AMD? Всё о Ryzen 9000 | Zen 5 с запасом
19:04
Мой Компьютер
Рет қаралды 96 М.
Лучшая защита экрана
0:40
Newtonlabs
Рет қаралды 1,3 МЛН