DevTestSecOps
138 subscribers
469 photos
29 videos
37 files
695 links
Forwards and notes on development, testing, security, and operations from @q587p.

About me: studied as System Architect, worked as a SysAdmin, working now as an Test Automation Engineer. Also, I'm interested in hacking (and everything related to it).

జ్
Download Telegram
Intent IQ QA Automation Home Task.docx
2 MB
#JobSeeking

Test task for #testing job, maybe someone else will be interested. 🙃
👍2
#comix

“Gently Down the Stream” – a gentle introduction to #stream processing and Apache #Kafka.

A group of otters discover that they can use a giant river to communicate with each other. As more otters move into the forest, they must learn to adapt their system to cope with the increased forest activity.

25 slides:

https://www.gentlydownthe.stream/
🥰2😱1
Psychedelic cryptography is a way of concealing messages (normally in videos) so that only people who’ve taken LSD can receive the messages. 🤪

https://qri.org/blog/psycrypto-contest
🔥1🤯1🦄1
👌2😁1💯1
#security #hack #OAuth

Dylan from truffleSecurity talks about a simple hole (it seems a bit loud to call it a vulnerability) that allows users of companies that use #Google authorization in services like Slack or Zoom to continue to have access even after being fired and having their access removed.

The hole is that such services use email as the user ID. But, obviously, you can create several different email addresses that receive the same emails (e.g. by adding words after "+"):

https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/
👏1👨‍💻1
1👎1👏1🤔1
The Microsoft security team detected a nation-state attack on our corporate systems on January 12, 2024, and immediately activated our response process to investigate, disrupt malicious activity, mitigate the attack, and deny the threat actor further access. Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium. As part of our ongoing commitment to responsible transparency as recently affirmed in our Secure Future Initiative (SFI), we are sharing this update.  

https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/
🤯2🔥1