really quality content, you explained it really well
@harwindersandhu67943 жыл бұрын
Good Content, keep it up. One Question, in your macOS terminal screenshots, how are you displaying "Apple" and "Home" icons?
@AidanGlickman3 жыл бұрын
Thanks! That comes from the Powerlevel10k theme.
@Manishkumar-pv7zg3 жыл бұрын
what is the step to perform these attack
@AidanGlickman3 жыл бұрын
I go over a basic blueprint in the video, but at a basic level an attacker would find the name of a private dependency, and upload a public package with the same name and a higher version number that contains malicious pre-install code which phones home to a network controlled by the attacker.
@aging52803 жыл бұрын
I'm stoked everywhere. How on earth did he included his dns or backdoor url to the json file
@AidanGlickman3 жыл бұрын
He used a DNS exfiltration technique where he encoded all of the data that he was getting out of the system as part of the DNS query he was making, and then his custom nameserver was set to log every request it received. From there he could easily read the data back out.
@aging52803 жыл бұрын
Thanks for early replay bro.
@aging52803 жыл бұрын
I don't really understand this so well. I saw the exact code he use to create the backdoor but I don't know how he included his dns server on the target depency
@AidanGlickman3 жыл бұрын
He included it in the preinstall hook, where a dependency can call an arbitrary script when it is downloaded. This is normally used to download external dependencies and binaries, but can be used maliciously as well.
@aging52803 жыл бұрын
Thanks for your hard work. You deserve me as a subscriber
@CharleyDC5R3 жыл бұрын
Is Maven also impacted by this?
@AidanGlickman3 жыл бұрын
Maven/Gradle is impacted. Gradle put out a deck on mitigation strategies here: www.jfokus.se/jfokus20-preso/Protecting-your-organization-against-attacks-via-the-build-system.pdf
@sealsquadgaming79943 жыл бұрын
Can you please elaborate how to find package names ??
@pyrosophy6803 жыл бұрын
Hey, that's quality content and you just got a subscriber. Pay attention to your body posture (keep your chin a bit more downwards for example). Keep it up, you will grow fast.