DevTestSecOps
138 subscribers
469 photos
29 videos
37 files
695 links
Forwards and notes on development, testing, security, and operations from @q587p.

About me: studied as System Architect, worked as a SysAdmin, working now as an Test Automation Engineer. Also, I'm interested in hacking (and everything related to it).

జ్
Download Telegram
Forwarded from gerontion
😁4
DevTestSecOps
#hack #Okta again!? https://sec.okta.com/harfiles
#hack #way

A good example of a suspected security breach report from !#1password
They suspected that something was going on in their #Okta account, i.e. all sorts of internal admin and helpdesk stuff.

A member of the IT team handled Okta support and, at their request, created a HAR file from Chrome Dev Tools and uploaded it to the Okta support portal. This HAR file contains a record of all traffic between the browser and Okta's servers, including sensitive information including session cookies. In the early morning hours of Friday, September 29, an unknown attacker used the same Okta session used to create the HAR file to access the Okta administration portal and attempted the following:

- Attempted to access an IT employee's user dashboard, but the attempt was blocked by the Okta system.

- Updated the existing IDP tied to our Google production environment.

- Activated the IDP.

- Requested an admin user report.

The last action on this list resulted in an alert email being sent to a member of the IT team, which of course resulted in a quick response.

More details:

https://blog.1password.com/files/okta-incident/okta-incident-report.pdf
👏2🤔2
👏2😁21
👻2😁1
Forwarded from тазашо🇺🇦
😁3👏1👻1🎃1
DevTestSecOps
#programming #Rust
#Rust #way

Found the original - the quote is taken from here:

A few years ago, I dropped everything to focus 100% on WebAssembly. At the time, Rust had the best support for compiling into WebAssembly, and the most full-featured WebAssembly runtimes were Rust-based. Rust was the best option on the menu. I jumped in, eager to see what all the hype was about.

Since then, I (along with some other awesome people) built Wick, an application framework and runtime that uses WebAssembly as its core module system.

Wick was the primary target of our Rust experimentation
After three years, multiple production deployments, an ebook, and ~100 packages deployed on
crates.io, I feel it’s time to share some thoughts on Rust:

https://jsoverson.medium.com/was-rust-worth-it-f43d171fb1b3
🤔1
Forwarded from Memus Occultus
😁2
#hack

If you are using any version of #Confluence, it is a good idea to backup all your data immediately. A vulnerability has been discovered that allows to modify and delete page and file content. Not only cloud instances are vulnerable, but also those located in user data centers:

https://arstechnica.com/security/2023/11/critical-vulnerability-in-atlassian-confluence-server-is-under-mass-exploitation/
🔥1😱1
😁2
#programming #date

At first I didn't understand, and then when I did!.. 🤪
😁2👏1😱1