HN user

frothy-dashcam

7 karma
Posts0
Comments3
View on HN
No posts found.

I absolutely second the OP. I used to be a penetration tester and whenever I had low level contributor access to an internal repository I managed to break out into the cloud and in 99% of cases I was an administrator after that. CI/CD is remote code execution as a service and way too often way too misconfigured. When I say low-level contributor access, I mean the level you give an intern who joins your company for a two-week summer internship. They come as an unpaid intern, they leave as an AWS administrator. Pretty good deal in my book ;) Thank you so much for creating the tool. This might drive the point home just how easy it is to exploit this stuff.

On a sidenote: the game ist (fun) advertisment for a website selling a book. When I visit this site (me sitting in Europe) they immediately set the _ga cookie (tested on vanilla Chrome on purpose). There is no privacy banner at all, they just set the cookie. They probably left out the banner to save my time, no?

EDIT: gumroad sets the cookie, not bigdatagirl. Does that make it better?