I absolutely second the OP. I used to be a penetration tester and whenever I had low level contributor access to an internal repository I managed to break out into the cloud and in 99% of cases I was an administrator after that. CI/CD is remote code execution as a service and way too often way too misconfigured. When I say low-level contributor access, I mean the level you give an intern who joins your company for a two-week summer internship. They come as an unpaid intern, they leave as an AWS administrator. Pretty good deal in my book ;) Thank you so much for creating the tool. This might drive the point home just how easy it is to exploit this stuff.
HN user
frothy-dashcam
7 karma
Posts0
Comments3
No posts found.
Show HN: SmokedMeat, like Metasploit, but for CI/CD (open-source) 3 months ago
Loved the read. I read enough dry stuff all day so this was a nice break :)
Cookie Consent Speed Running Game 5 years ago
On a sidenote: the game ist (fun) advertisment for a website selling a book. When I visit this site (me sitting in Europe) they immediately set the _ga cookie (tested on vanilla Chrome on purpose). There is no privacy banner at all, they just set the cookie. They probably left out the banner to save my time, no?
EDIT: gumroad sets the cookie, not bigdatagirl. Does that make it better?