RomHack 2024 - Adnan Khan - The dark side of github actions

  Рет қаралды 73

Cyber Saiyan

Cyber Saiyan

Күн бұрын

Adnan Khan
The dark side of github actions
slides: romhack.io/wp-...
GitHub is the most popular hosting platform for open-source projects. GitHub also offers a CI/CD platform called GitHub Actions, and many projects opt to use GitHub Actions for CI/CD because it is free for open-source projects.
However, there is a dark side to GitHub Actions. Simple misconfigurations can lead to devastating supply chain attacks, and even companies like Microsoft, Nvidia, Puppet Labs, and more cannot get a handle on these issues.
In this talk you’ll learn what these misconfigurations are and how to discover them at scale:
Pwn Request and Injection Vulnerabilities
Misconfigured Self-Hosted Runners
Broken Approval Checks via Time-of-Check-Time-of-Use Issues
You will also learn how an attacker can use an arsenal of pipeline post-exploitation and privilege escalation techniques to achieve their objectives:
Post-Compromise Enumeration
‘GITHUB_TOKEN’ Permissions Abuse
GitHub Actions Cache Poisoning
Bypassing Branch Protections by approving and merging an external pull request.
Finally, Adnan will walk through how he detected such a misconfiguration by a major company, gained control of a GitHub Classic Personal Access Token, and proved out impactful post-exploitation scenarios. To conclude, Adnan will cover defensive controls that you can deploy today that will prevent an attacker from achieving their final objective even if they obtain a privileged access token.
romhack.io/rom...

Пікірлер
Is Computer Science still worth it?
20:08
NeetCodeIO
Рет қаралды 368 М.
Help Me Celebrate! 😍🙏
00:35
Alan Chikin Chow
Рет қаралды 69 МЛН
小路飞嫁祸姐姐搞破坏 #路飞#海贼王
00:45
路飞与唐舞桐
Рет қаралды 26 МЛН
Life hack 😂 Watermelon magic box! #shorts by Leisi Crazy
00:17
Leisi Crazy
Рет қаралды 70 МЛН
Creator of git, Linus Torvalds Presents the Fundamentals of git
1:10:15
Developers Alliance
Рет қаралды 103 М.
Creating a window - Software from Scratch (Ep. 1)
1:04:12
Muukid
Рет қаралды 47 М.
#RomHack2022 - Edoardo Rosa - You shall not PassRole!
40:18
Cyber Saiyan
Рет қаралды 275
NSURLProtocol: How I Stole an App For My Wedding
56:25
Bryce Bostwick
Рет қаралды 41 М.