hacking: security in practice
I want to download a keylogger onto my computer.
Not a hostile one but one that while spit back a txt file or something like that to track activity on my account for a project
submitted by /u/TheRougeGeo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I want to download a keylogger onto my computer.
Not a hostile one but one that while spit back a txt file or something like that to track activity on my account for a project
submitted by /u/TheRougeGeo
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I want to download a keylogger onto my computer.
Not a hostile one but one that while spit back a txt file or something like that to track activity on my account for a project
VulnLab SQL Injection— Dynamic Application Security Testing #3
https://muh-hidayat7799.medium.com/vulnlab-sql-injection-dynamic-application-security-testing-3-2138d56dbe03?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://muh-hidayat7799.medium.com/vulnlab-sql-injection-dynamic-application-security-testing-3-2138d56dbe03?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
VulnLab SQL Injection— Dynamic Application Security Testing #3
Assalamualaikum Wr.Wb
Assalamualaikum Wr.WbContinue reading on Medium » (https://muh-hidayat7799.medium.com/vulnlab-sql-injection-dynamic-application-security-testing-3-2138d56dbe03?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
VulnLab SQL Injection— Dynamic Application Security Testing #3
Assalamualaikum Wr.Wb
iOS jailbreak dev wins $2M bounty for finding critical Optimism bug
https://medium.com/@thebittimes.com/ios-jailbreak-dev-wins-2m-bounty-for-finding-critical-optimism-bug-e412ad64b2c5?source=rss------bug_bounty-5
Continue reading on Medium » (https://medium.com/@thebittimes.com/ios-jailbreak-dev-wins-2m-bounty-for-finding-critical-optimism-bug-e412ad64b2c5?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@thebittimes.com/ios-jailbreak-dev-wins-2m-bounty-for-finding-critical-optimism-bug-e412ad64b2c5?source=rss------bug_bounty-5
Continue reading on Medium » (https://medium.com/@thebittimes.com/ios-jailbreak-dev-wins-2m-bounty-for-finding-critical-optimism-bug-e412ad64b2c5?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
iOS jailbreak dev wins $2M bounty for finding critical Optimism bug
Ethereum scaling startup Optimism disclosed a “critical bug” fix in the project’s Geth fork that would have allowed malicious hackers to create infinite ETH Developers from the Ethereum Layer 2…
VulnLab SQL Injection— Dynamic Application Security Testing #3
Assalamualaikum Wr.WbContinue reading on Medium »
Read more...
Assalamualaikum Wr.WbContinue reading on Medium »
Read more...
iOS jailbreak dev wins $2M bounty for finding critical Optimism bug
Continue reading on Medium »
Read more...
Continue reading on Medium »
Read more...
hacking: security in practice
How to get over the unrecognized app/publisher warning in Windows
All,
I am writing an executable to put on a website for download. Every time I go to download it, I get an "unrecognized app, unknown publisher warning".
It's not tagged as malicious, but it's tagged as "unknown publisher" which makes it appear that way. Does anyone know how to add a publisher? Is that something a non-corporation can do? Or could I at least add a certificate or something to make WIndows calm down?
submitted by /u/iExtrapolate314
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to get over the unrecognized app/publisher warning in Windows
All,
I am writing an executable to put on a website for download. Every time I go to download it, I get an "unrecognized app, unknown publisher warning".
It's not tagged as malicious, but it's tagged as "unknown publisher" which makes it appear that way. Does anyone know how to add a publisher? Is that something a non-corporation can do? Or could I at least add a certificate or something to make WIndows calm down?
submitted by /u/iExtrapolate314
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to get over the unrecognized app/publisher warning in Windows
All, I am writing an executable to put on a website for download. Every time I go to download it, I get an "unrecognized app, unknown publisher...
hacking: security in practice
Shutdown-i command treat?
Hi, i work for a big alimentation company. I discovered that on workstation i can enter the admin cmd and have acces to the shutdown -i command. When i search for computers i see over a 1000 computers and servers. I dont know nothing about hacking or cybersecurity and im wondering if its a treat and should tell my boss. Thanks for your advice!
submitted by /u/V16mike
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Shutdown-i command treat?
Hi, i work for a big alimentation company. I discovered that on workstation i can enter the admin cmd and have acces to the shutdown -i command. When i search for computers i see over a 1000 computers and servers. I dont know nothing about hacking or cybersecurity and im wondering if its a treat and should tell my boss. Thanks for your advice!
submitted by /u/V16mike
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Shutdown-i command treat?
Hi, i work for a big alimentation company. I discovered that on workstation i can enter the admin cmd and have acces to the shutdown -i command....
Retrieving Syscall ID with Hell's Gate, Halo's Gate, FreshyCalls and Syswhispers2
https://www.reddit.com/r/redteamsec/comments/spt6x8/retrieving_syscall_id_with_hells_gate_halos_gate/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://alice.climent-pommeret.red/posts/direct-syscalls-hells-halos-syswhispers2/) [comments] (https://www.reddit.com/r/redteamsec/comments/spt6x8/retrieving_syscall_id_with_hells_gate_halos_gate/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/spt6x8/retrieving_syscall_id_with_hells_gate_halos_gate/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://alice.climent-pommeret.red/posts/direct-syscalls-hells-halos-syswhispers2/) [comments] (https://www.reddit.com/r/redteamsec/comments/spt6x8/retrieving_syscall_id_with_hells_gate_halos_gate/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Retrieving Syscall ID with Hell's Gate, Halo's Gate, FreshyCalls...
Posted in r/redteamsec by u/dmchell • 1 point and 0 comments
🔥🔥 A new version 0.1.3 released for Kubesploit: a post-exploitation framework for Kubernetes🔥🔥
https://www.reddit.com/r/redteamsec/comments/spv961/a_new_version_013_released_for_kubesploit_a/
submitted by /u/kubiscan (https://www.reddit.com/user/kubiscan)
[link] (https://github.com/cyberark/kubesploit/) [comments] (https://www.reddit.com/r/redteamsec/comments/spv961/a_new_version_013_released_for_kubesploit_a/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/spv961/a_new_version_013_released_for_kubesploit_a/
submitted by /u/kubiscan (https://www.reddit.com/user/kubiscan)
[link] (https://github.com/cyberark/kubesploit/) [comments] (https://www.reddit.com/r/redteamsec/comments/spv961/a_new_version_013_released_for_kubesploit_a/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
🔥🔥 A new version 0.1.3 released for Kubesploit: a...
Posted in r/redteamsec by u/kubiscan • 8 points and 1 comment
Introduction to Spring Boot Related Vulnerabilities
https://medium.com/@TutorialBoy24/introduction-to-spring-boot-related-vulnerabilities-35fb73f558fd?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@TutorialBoy24/introduction-to-spring-boot-related-vulnerabilities-35fb73f558fd?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Introduction to Spring Boot Related Vulnerabilities
Spring Boot related vulnerability learning materials, collection of utilization methods and skills, black box security assessment checklist
Spring Boot related vulnerability learning materials, collection of utilization methods and skills, black box security assessment checklistContinue reading on Medium » (https://medium.com/@TutorialBoy24/introduction-to-spring-boot-related-vulnerabilities-35fb73f558fd?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Introduction to Spring Boot Related Vulnerabilities
Spring Boot related vulnerability learning materials, collection of utilization methods and skills, black box security assessment checklist
Black Hat Ethical Hacking
Apple patches new zero-day exploited to hack iPhones, iPads, Macs
___________________________
@hacking_Attack
@Hacking_Video
Apple patches new zero-day exploited to hack iPhones, iPads, Macs
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Apple patches new zero-day exploited to hack iPhones, iPads, Macs | Black Hat Ethical Hacking
Apple has released security updates to fix a new zero-day vulnerability exploited in the wild by attackers to hack iPhones, iPads, and Macs.
Basic Web technologies required for starting with the web Exploitation Part-2
Hello Myself Manan Aggarwal is here to present the Blog about the Basic Web technologies required for starting with the web Exploitation…Continue reading on Medium »
Read more...
Hello Myself Manan Aggarwal is here to present the Blog about the Basic Web technologies required for starting with the web Exploitation…Continue reading on Medium »
Read more...
TerraGoat - Vulnerable Terraform Infrastructure
http://www.kitploit.com/2022/02/terragoat-vulnerable-terraform.html
http://www.kitploit.com/2022/02/terragoat-vulnerable-terraform.html
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
Introduction TerraGoat was built to enable DevSecOps design and implement a sustainable misconfiguration (https://www.kitploit.com/search/label/Misconfiguration) prevention strategy. It can be used to test a policy-as-code framework like Bridgecrew (https://bridgecrew.io/?utm_source=github&utm_medium=organic_oss&utm_campaign=terragoat) & Checkov (https://github.com/bridgecrewio/checkov/), inline-linters, pre-commit hooks or other code scanning methods. TerraGoat follows the tradition of existing *Goat projects that provide a baseline training ground to practice implementing secure development (https://www.kitploit.com/search/label/Secure%20Development) best practices for cloud infrastructure. Important notes Where to get help: the Bridgecrew Community Slack (https://slack.bridgecrew.io/?utm_source=github&utm_medium=organic_oss&utm_campaign=terragoat) Before you proceed please take a not of these warning: TerraGoat creates intentionally vulnerable AWS resources into your account. DO NOT deploy TerraGoat in a production environment or alongside any sensitive AWS resources. Requirements Terraform 0.12 aws cli azure cli To prevent vulnerable infrastructure (https://www.kitploit.com/search/label/Vulnerable%20Infrastructure) from arriving to production see: Bridgecrew (https://bridgecrew.io/?utm_source=github&utm_medium=organic_oss&utm_campaign=terragoat) & checkov (https://github.com/bridgecrewio/checkov/), the open source static analysis (https://www.kitploit.com/search/label/Static%20Analysis) tool for infrastructure (https://www.kitploit.com/search/label/Infrastructure) as code. Getting started AWS Setup Installation (AWS) You can deploy multiple TerraGoat stacks in a single AWS account using the parameter TF_VAR_environment. Create an S3 Bucket backend to keep Terraform state export TERRAGOAT_STATE_BUCKET="mydevsecops-bucket"
export TF_VAR_company_name=acme
export TF_VAR_environment=mydevsecops
export TF_VAR_region="us-west-2"
aws s3api create-bucket --bucket $TERRAGOAT_STATE_BUCKET \
--region $TF_VAR_region --create-bucket-configuration LocationConstraint=$TF_VAR_region
# Enable versioning
aws s3api put-bucket-versioning --bucket $TERRAGOAT_STATE_BUCKET --versioning-configuration Status=Enabled
# Enable encryption
aws s3api put-bucket-encryption --bucket $TERRAGOAT_STATE_BUCKET --server-side-encryption-configuration '{
"Rules": [
{
"ApplyServerSideEncryptionByDefault": {
"SSEAlgorithm": "aws:kms"
}
}
]
}' Apply TerraGoat (AWS) cd terraform/aws/
terraform init \
-backend-config="bucket=$TERRAGOAT_STATE_BUCKET" \
-backend-config="key=$TF_VAR_company_name-$TF_VAR_environment.tfstate" \
-backend-config="region=$TF_VAR_region"
terraform apply Remove TerraGoat (AWS) terraform destroy Creating multiple TerraGoat AWS stacks cd terraform/aws/
export TERRAGOAT_ENV=$TF_VAR_environment
export TERRAGOAT_STACKS_NUM=5
for i in $(seq 1 $TERRAGOAT_STACKS_NUM)
do
export TF_VAR_environment=$TERRAGOAT_ENV$i
terraform init \
-backend-config="bucket=$TERRAGOAT_STATE_BUCKET" \
-backend-config="key=$TF_VAR_company_name-$TF_VAR_environment.tfstate" \
-backend-config="region=$TF_VAR_region"
terraform apply -auto-approve
done Deleting multiple TerraGoat stacks (AWS) cd terraform/aws/
export TF_VAR_environment = $TERRAGOAT_ENV
for i in $(seq 1 $TERRAGOAT_STACKS_NUM)
do
export TF_VAR_environment=$TERRAGOAT_ENV$i
terraform init \
-backend-config="bucket=$TERRAGOAT_STATE_BUCKET" \
-backend-config="key=$TF_VAR_company_name-$TF_VAR_environment.tfstate" \
-backend-config="region=$TF_VAR_region"
terraform destroy -auto-approve
Introduction TerraGoat was built to enable DevSecOps design and implement a sustainable misconfiguration (https://www.kitploit.com/search/label/Misconfiguration) prevention strategy. It can be used to test a policy-as-code framework like Bridgecrew (https://bridgecrew.io/?utm_source=github&utm_medium=organic_oss&utm_campaign=terragoat) & Checkov (https://github.com/bridgecrewio/checkov/), inline-linters, pre-commit hooks or other code scanning methods. TerraGoat follows the tradition of existing *Goat projects that provide a baseline training ground to practice implementing secure development (https://www.kitploit.com/search/label/Secure%20Development) best practices for cloud infrastructure. Important notes Where to get help: the Bridgecrew Community Slack (https://slack.bridgecrew.io/?utm_source=github&utm_medium=organic_oss&utm_campaign=terragoat) Before you proceed please take a not of these warning: TerraGoat creates intentionally vulnerable AWS resources into your account. DO NOT deploy TerraGoat in a production environment or alongside any sensitive AWS resources. Requirements Terraform 0.12 aws cli azure cli To prevent vulnerable infrastructure (https://www.kitploit.com/search/label/Vulnerable%20Infrastructure) from arriving to production see: Bridgecrew (https://bridgecrew.io/?utm_source=github&utm_medium=organic_oss&utm_campaign=terragoat) & checkov (https://github.com/bridgecrewio/checkov/), the open source static analysis (https://www.kitploit.com/search/label/Static%20Analysis) tool for infrastructure (https://www.kitploit.com/search/label/Infrastructure) as code. Getting started AWS Setup Installation (AWS) You can deploy multiple TerraGoat stacks in a single AWS account using the parameter TF_VAR_environment. Create an S3 Bucket backend to keep Terraform state export TERRAGOAT_STATE_BUCKET="mydevsecops-bucket"
export TF_VAR_company_name=acme
export TF_VAR_environment=mydevsecops
export TF_VAR_region="us-west-2"
aws s3api create-bucket --bucket $TERRAGOAT_STATE_BUCKET \
--region $TF_VAR_region --create-bucket-configuration LocationConstraint=$TF_VAR_region
# Enable versioning
aws s3api put-bucket-versioning --bucket $TERRAGOAT_STATE_BUCKET --versioning-configuration Status=Enabled
# Enable encryption
aws s3api put-bucket-encryption --bucket $TERRAGOAT_STATE_BUCKET --server-side-encryption-configuration '{
"Rules": [
{
"ApplyServerSideEncryptionByDefault": {
"SSEAlgorithm": "aws:kms"
}
}
]
}' Apply TerraGoat (AWS) cd terraform/aws/
terraform init \
-backend-config="bucket=$TERRAGOAT_STATE_BUCKET" \
-backend-config="key=$TF_VAR_company_name-$TF_VAR_environment.tfstate" \
-backend-config="region=$TF_VAR_region"
terraform apply Remove TerraGoat (AWS) terraform destroy Creating multiple TerraGoat AWS stacks cd terraform/aws/
export TERRAGOAT_ENV=$TF_VAR_environment
export TERRAGOAT_STACKS_NUM=5
for i in $(seq 1 $TERRAGOAT_STACKS_NUM)
do
export TF_VAR_environment=$TERRAGOAT_ENV$i
terraform init \
-backend-config="bucket=$TERRAGOAT_STATE_BUCKET" \
-backend-config="key=$TF_VAR_company_name-$TF_VAR_environment.tfstate" \
-backend-config="region=$TF_VAR_region"
terraform apply -auto-approve
done Deleting multiple TerraGoat stacks (AWS) cd terraform/aws/
export TF_VAR_environment = $TERRAGOAT_ENV
for i in $(seq 1 $TERRAGOAT_STACKS_NUM)
do
export TF_VAR_environment=$TERRAGOAT_ENV$i
terraform init \
-backend-config="bucket=$TERRAGOAT_STATE_BUCKET" \
-backend-config="key=$TF_VAR_company_name-$TF_VAR_environment.tfstate" \
-backend-config="region=$TF_VAR_region"
terraform destroy -auto-approve
export TERRAGOAT_STATE_STORAGE_ACCOUNT="mydevsecopssa"
export TERRAGOAT_STATE_CONTAINER="mydevsecops"
export TF_VAR_environment="dev"
export TF_VAR_region="westus"
# Create resource group
az group create --location $TF_VAR_region --name $TERRAGOAT_RESOURCE_GROUP
# Create storage account
az storage account create --name $TERRAGOAT_STATE_STORAGE_ACCOUNT --resource-group $TERRAGOAT_RESOURCE_GROUP --location $TF_VAR_region --sku Standard_LRS --kind StorageV2 --https-only true --encryption-services blob
# Get storage account key
ACCOUNT_KEY=$(az storage account keys list --resource-group $TERRAGOAT_RESOURCE_GROUP --account-name $TERRAGOAT_STATE_STORAGE_ACCOUNT --query [0].value -o tsv)
# Create blob container
az storage container create --name $TERRAGOAT_STATE_CONTAINER --account-name $TERRAGOAT_STATE_STORAGE_ACCOUNT --account-key $ACCOUNT_KEY Apply TerraGoat (Azure) cd terraform/azure/
terraform init -reconfigure -backend-config="resource_group_name=$TERRAGOAT_RESOURCE_GROUP" \
-backend-config "storage_account_name=$TERRAGOAT_STATE_STORAGE_ACCOUNT" \
-backend-config="container_name=$TERRAGOAT_STATE_CONTAINER" \
-backend-config "key=$TF_VAR_environment.terraform.tfstate"
terraform apply Remove TerraGoat (Azure) terraform destroy GCP Setup Installation (GCP) You can deploy multiple TerraGoat stacks in a single GCP project using the parameter TF_VAR_environment. Create a GCS backend to keep Terraform state To use terraform, a Service Account and matching set of credentials are required. If they do not exist, they must be manually created for the relevant project. To create the Service Account: Sign into your GCP project, go to IAM > Service Accounts. Click the CREATE SERVICE ACCOUNT. Give a name to your service account (for example - terragoat) and click CREATE. Grant the Service Account the Project > Editor role and click CONTINUE. Click DONE. To create the credentials: Sign into your GCP project, go to IAM > Service Accounts and click on the relevant Service Account. Click ADD KEY > Create new key > JSON and click CREATE. This will create a .json file and download it to your computer. We recommend saving the key with a nicer name than the auto-generated one (i.e. terragoat_credentials.json), and storing the resulting JSON file inside terraform/gcp directory of terragoat. Once the credentials are set up, create the BE configuration as follows: # example: export TF_VAR_credentials_path=terragoat_credentials.json export TF_VAR_project= # Create storage bucket gsutil mb gs://${TF_TERRAGOAT_STATE_BUCKET}'>export TF_VAR_environment="dev"
export TF_TERRAGOAT_STATE_BUCKET=remote-state-bucket-terragoat
export TF_VAR_credentials_path= # example: export TF_VAR_credentials_path=terragoat_credentials.json
export TF_VAR_project=
# Create storage bucket
gsutil mb gs://${TF_TERRAGOAT_STATE_BUCKET} Apply TerraGoat (GCP) cd terraform/gcp/
terraform init -reconfigure -backend-config="bucket=$TF_TERRAGOAT_STATE_BUCKET" \
-backend-config "credentials=$TF_VAR_credentials_path" \
-backend-config "prefix=terragoat/${TF_VAR_environment}"
terraform apply Remove TerraGoat (GCP) terraform destroy Bridgecrew's IaC herd of goats CfnGoat (https://github.com/bridgecrewio/cfngoat) - Vulnerable by design Cloudformation template TerraGoat (https://github.com/bridgecrewio/terragoat) - Vulnerable by design Terraform stack CDKGoat (https://github.com/bridgecrewio/cdkgoat) - Vulnerable by design CDK application Contributing Contribution is welcomed! We would love to hear about more ideas on how to find vulnerable infrastructure-as-code design patterns. Support Bridgecrew (https://bridgecrew.io/?utm_source=github&utm_medium=organic_oss&utm_campaign=terragoat) builds and maintains TerraGoat to encourage the adoption of policy-as-code. If you need direct support you can contact us at info@bridgecrew.io (mailto:info@bridgecrew.io).
export TERRAGOAT_STATE_CONTAINER="mydevsecops"
export TF_VAR_environment="dev"
export TF_VAR_region="westus"
# Create resource group
az group create --location $TF_VAR_region --name $TERRAGOAT_RESOURCE_GROUP
# Create storage account
az storage account create --name $TERRAGOAT_STATE_STORAGE_ACCOUNT --resource-group $TERRAGOAT_RESOURCE_GROUP --location $TF_VAR_region --sku Standard_LRS --kind StorageV2 --https-only true --encryption-services blob
# Get storage account key
ACCOUNT_KEY=$(az storage account keys list --resource-group $TERRAGOAT_RESOURCE_GROUP --account-name $TERRAGOAT_STATE_STORAGE_ACCOUNT --query [0].value -o tsv)
# Create blob container
az storage container create --name $TERRAGOAT_STATE_CONTAINER --account-name $TERRAGOAT_STATE_STORAGE_ACCOUNT --account-key $ACCOUNT_KEY Apply TerraGoat (Azure) cd terraform/azure/
terraform init -reconfigure -backend-config="resource_group_name=$TERRAGOAT_RESOURCE_GROUP" \
-backend-config "storage_account_name=$TERRAGOAT_STATE_STORAGE_ACCOUNT" \
-backend-config="container_name=$TERRAGOAT_STATE_CONTAINER" \
-backend-config "key=$TF_VAR_environment.terraform.tfstate"
terraform apply Remove TerraGoat (Azure) terraform destroy GCP Setup Installation (GCP) You can deploy multiple TerraGoat stacks in a single GCP project using the parameter TF_VAR_environment. Create a GCS backend to keep Terraform state To use terraform, a Service Account and matching set of credentials are required. If they do not exist, they must be manually created for the relevant project. To create the Service Account: Sign into your GCP project, go to IAM > Service Accounts. Click the CREATE SERVICE ACCOUNT. Give a name to your service account (for example - terragoat) and click CREATE. Grant the Service Account the Project > Editor role and click CONTINUE. Click DONE. To create the credentials: Sign into your GCP project, go to IAM > Service Accounts and click on the relevant Service Account. Click ADD KEY > Create new key > JSON and click CREATE. This will create a .json file and download it to your computer. We recommend saving the key with a nicer name than the auto-generated one (i.e. terragoat_credentials.json), and storing the resulting JSON file inside terraform/gcp directory of terragoat. Once the credentials are set up, create the BE configuration as follows: # example: export TF_VAR_credentials_path=terragoat_credentials.json export TF_VAR_project= # Create storage bucket gsutil mb gs://${TF_TERRAGOAT_STATE_BUCKET}'>export TF_VAR_environment="dev"
export TF_TERRAGOAT_STATE_BUCKET=remote-state-bucket-terragoat
export TF_VAR_credentials_path= # example: export TF_VAR_credentials_path=terragoat_credentials.json
export TF_VAR_project=
# Create storage bucket
gsutil mb gs://${TF_TERRAGOAT_STATE_BUCKET} Apply TerraGoat (GCP) cd terraform/gcp/
terraform init -reconfigure -backend-config="bucket=$TF_TERRAGOAT_STATE_BUCKET" \
-backend-config "credentials=$TF_VAR_credentials_path" \
-backend-config "prefix=terragoat/${TF_VAR_environment}"
terraform apply Remove TerraGoat (GCP) terraform destroy Bridgecrew's IaC herd of goats CfnGoat (https://github.com/bridgecrewio/cfngoat) - Vulnerable by design Cloudformation template TerraGoat (https://github.com/bridgecrewio/terragoat) - Vulnerable by design Terraform stack CDKGoat (https://github.com/bridgecrewio/cdkgoat) - Vulnerable by design CDK application Contributing Contribution is welcomed! We would love to hear about more ideas on how to find vulnerable infrastructure-as-code design patterns. Support Bridgecrew (https://bridgecrew.io/?utm_source=github&utm_medium=organic_oss&utm_campaign=terragoat) builds and maintains TerraGoat to encourage the adoption of policy-as-code. If you need direct support you can contact us at info@bridgecrew.io (mailto:info@bridgecrew.io).