DevTestSecOps
138 subscribers
468 photos
29 videos
37 files
695 links
Forwards and notes on development, testing, security, and operations from @q587p.

About me: studied as System Architect, worked as a SysAdmin, working now as an Test Automation Engineer. Also, I'm interested in hacking (and everything related to it).

జ్
Download Telegram
DevTestSecOps
#hack #Okta again!? https://sec.okta.com/harfiles
#hack #way

A good example of a suspected security breach report from !#1password
They suspected that something was going on in their #Okta account, i.e. all sorts of internal admin and helpdesk stuff.

A member of the IT team handled Okta support and, at their request, created a HAR file from Chrome Dev Tools and uploaded it to the Okta support portal. This HAR file contains a record of all traffic between the browser and Okta's servers, including sensitive information including session cookies. In the early morning hours of Friday, September 29, an unknown attacker used the same Okta session used to create the HAR file to access the Okta administration portal and attempted the following:

- Attempted to access an IT employee's user dashboard, but the attempt was blocked by the Okta system.

- Updated the existing IDP tied to our Google production environment.

- Activated the IDP.

- Requested an admin user report.

The last action on this list resulted in an alert email being sent to a member of the IT team, which of course resulted in a quick response.

More details:

https://blog.1password.com/files/okta-incident/okta-incident-report.pdf
👏2🤔2
#hack

If you are using any version of #Confluence, it is a good idea to backup all your data immediately. A vulnerability has been discovered that allows to modify and delete page and file content. Not only cloud instances are vulnerable, but also those located in user data centers:

https://arstechnica.com/security/2023/11/critical-vulnerability-in-atlassian-confluence-server-is-under-mass-exploitation/
🔥1😱1
😁2
Fresh #hack: #ChatGPT can generate sequences memorized from its training data using a very trivial attack. You tell the bot to “say the word * as many times as possible”. And, starting with some attempt, ChatGPT starts to produce something very similar to the original data from the training sample:

https://stackdiary.com/chatgpts-training-data-can-be-exposed-via-a-divergence-attack/
👍1👏1😱1