HN user

syntheticcorp

94 karma
Posts0
Comments67
View on HN
No posts found.

I get your point but I think pentesters are perfectly capable of thinking in graphs, including web security. Bug chains are the immediate example, where a couple of CVSS 4-7 vulns can be turned into a full rce/whatever 9.8 equivalent. This bug chaining fundamentally occurs via elements of compromise i.e a graph traversal.

Bloodhound is great, and a nice visual tool for people to conceptualise attack graphs but it’s just a part of the process of understanding the target domain from an attackers perspective. No nice tool like bloodhound exists for web pentesting because a chain of compromise can’t simply be reduced into tool form there because a chain is often specific to the app and not an underlying framework, unlike AD where the security boundaries are well(ish) understood and codified.

Pentest reports include stuff like SMB signing and “don’t admin everything with your DA account ” because they are glowing hot nodes very early in a chain of compromise, meaning that is often how stuff gets popped IRL. It’s (hopefully) not that the pentester doesn’t understand graph thinking, it’s just the the first node in the graph represents effectively complete compromise, so why traverse?

It’s pretty infrequent outside of target attacks. Most recent is probably the roundcube XSS CVE-2023-43770 that was actively exploited as 0day by a threat actor last year.

You can’t serve a valid certificate chain to the client even if you control their traffic, because your malicious certificate isn’t signed by a trusted CA. And you can’t get a CA signature without demonstrating control of the domain to a CA.

I’ve also encountered that a few times where a fairly anodyne bug in a codepath prevents a serious security bug from being reachable. With my attacker hat on it is very tempting to just report the first one…

Substack was down 4 years ago

Browsers already include this feature in a coarse grained (but utterly sufficient) manner in the form of a scroll bar.

I work in offense and they can be a huge impediment. Significant work goes into bypassing or staying undetected from these products. While not all the detection occurs at runtime, they report a lot of data back from the endpoint so historical detection can happen.

However what I see is essentially their true positive and false negative rate, I would be interested to know what the false positive rate is.

Founding Uber SRE 4 years ago

I’ve worked in tech in NZ for 7 years or so, never actually met someone who calls themselves an SRE. Obviously I know the term, but IME we don’t use that title here

Are you aware which website you’re on? Having strong opinions on esoteric topics is a HN mainstay. Also as a non-American driving in the US made me think about a lot of things I wouldn’t otherwise consider. (Yes you have too many stop signs)