hacking: security in practice
Grabbing an IP at work
SO.. for some reason, I like to make games for myself with networking.. This week, we are gonna attempt to grab my work's primary IP address!
I work in a factory that has assembly lines. My position, I work at the very end of the assembly line and verify if a part is good or not before boxing it up to be shipped out.
My station has a computer that is ethernet to the internet. Out of boredom, I wanted to see how easy it would be to grab the IP of my work/ the IP my work station runs off of.
I figured it was gonna be very simple. I just opened cmd and did ipconfig, but i was met with a private IP.. so i didn't get anywhere that way. This made me wanna dive deeper into how good our security is lol.
My 2nd attempt was to use powershell and see if i can find the public that way. i put in "Invoke-RestMethod ipinfo.io/ip" but i ran into errors.. not exactly sure what it said cuz i didnt want to leave the screen up too long and get my game busted.
so now.. im on attempt number 3.. but i wanna see what Reddit has to say!
Shortened up: how can i get the public IP(IPv4) of a computer i have access to/ how can I get the public IP(IPv4) of a connection near me?
submitted by /u/RubSumNubs
[link] [comments]
Grabbing an IP at work
SO.. for some reason, I like to make games for myself with networking.. This week, we are gonna attempt to grab my work's primary IP address!
I work in a factory that has assembly lines. My position, I work at the very end of the assembly line and verify if a part is good or not before boxing it up to be shipped out.
My station has a computer that is ethernet to the internet. Out of boredom, I wanted to see how easy it would be to grab the IP of my work/ the IP my work station runs off of.
I figured it was gonna be very simple. I just opened cmd and did ipconfig, but i was met with a private IP.. so i didn't get anywhere that way. This made me wanna dive deeper into how good our security is lol.
My 2nd attempt was to use powershell and see if i can find the public that way. i put in "Invoke-RestMethod ipinfo.io/ip" but i ran into errors.. not exactly sure what it said cuz i didnt want to leave the screen up too long and get my game busted.
so now.. im on attempt number 3.. but i wanna see what Reddit has to say!
Shortened up: how can i get the public IP(IPv4) of a computer i have access to/ how can I get the public IP(IPv4) of a connection near me?
submitted by /u/RubSumNubs
[link] [comments]
reddit
Grabbing an IP at work
SO.. for some reason, I like to make games for myself with networking.. This week, we are gonna attempt to grab my work's primary IP address! I...
hacking: security in practice
How to tell if my computer is hacked?
So last week I had some mishap on a video game and since then my GPU has been acting up. I'm not going to detail it here but you can read it on my other posts (and please do, I desperately want to fix this issue!)
Anyway though, someone on another website just said "WOW so lesson don't play MP crap games and if this has happened then your PC likey got hacked, I would be fully formatting the the OS drive and doing a clean install of windows and making sure that PC security setting are fully maxed out and up to date. And stay away from in game live chat"
The video game in question was VRchat, and the incident that occurred was someone using a game crashing avatar (intended to crash quest users) that was blasting audio with a very low poly avatar. I highly doubt something like that is capable of hacking my entire computer, seeing as the audio was playing through his microphone, and I only lagged for a moment after it happened. That, and I blocked him about 2 minutes before he made everyone's games mess up (so I'm honestly not sure why I was affected too but whatever).
Anyway, is it even possible for me to get hacked that way?
submitted by /u/logswithdogs
[link] [comments]
How to tell if my computer is hacked?
So last week I had some mishap on a video game and since then my GPU has been acting up. I'm not going to detail it here but you can read it on my other posts (and please do, I desperately want to fix this issue!)
Anyway though, someone on another website just said "WOW so lesson don't play MP crap games and if this has happened then your PC likey got hacked, I would be fully formatting the the OS drive and doing a clean install of windows and making sure that PC security setting are fully maxed out and up to date. And stay away from in game live chat"
The video game in question was VRchat, and the incident that occurred was someone using a game crashing avatar (intended to crash quest users) that was blasting audio with a very low poly avatar. I highly doubt something like that is capable of hacking my entire computer, seeing as the audio was playing through his microphone, and I only lagged for a moment after it happened. That, and I blocked him about 2 minutes before he made everyone's games mess up (so I'm honestly not sure why I was affected too but whatever).
Anyway, is it even possible for me to get hacked that way?
submitted by /u/logswithdogs
[link] [comments]
reddit
How to tell if my computer is hacked?
So last week I had some mishap on a video game and since then my GPU has been acting up. I'm not going to detail it here but you can read it on my...
hacking: security in practice
How do I figure out someone’s identity through an anonymous app?
There is an app on the app store called “chitter” that is mainly used by children and pedophiles. The pedophiles on there sell/ trade child pornography as well as pray on the children who are also on the app. I’m not even kidding when I say they will have names such as “m 40 for underage” like they aren’t even being sneaky with it. It is extremely disturbing not being able to do anything about it and that they get to live in society with absolutely no fear of getting caught for their actions and a lot of them have jobs that involve children. Most of these pedos live in either the UK, USA, or Canada. Is there anyway at all that I can trace down their identities?
submitted by /u/Early_Ad_4442
[link] [comments]
How do I figure out someone’s identity through an anonymous app?
There is an app on the app store called “chitter” that is mainly used by children and pedophiles. The pedophiles on there sell/ trade child pornography as well as pray on the children who are also on the app. I’m not even kidding when I say they will have names such as “m 40 for underage” like they aren’t even being sneaky with it. It is extremely disturbing not being able to do anything about it and that they get to live in society with absolutely no fear of getting caught for their actions and a lot of them have jobs that involve children. Most of these pedos live in either the UK, USA, or Canada. Is there anyway at all that I can trace down their identities?
submitted by /u/Early_Ad_4442
[link] [comments]
reddit
How do I figure out someone’s identity through an anonymous app?
There is an app on the app store called “chitter” that is mainly used by children and pedophiles. The pedophiles on there sell/ trade child...
hacking: security in practice
Can Android phones be hacked by calling
First of all I am from India and today I received a suspicious call that lasted 19 sec.
After I picked up the call no one talked to me for about 10 sec, just when I was about to hang up someone said that they are calling from Bajaj finance and if I wanted a loan, as soon as I said no they themselves hung up the call.
All this looks pretty suspicious to me so I thought any expert on the matter could help because one thing is for sure that it wasn't a call from customer service. Also my phones location was turned off.
submitted by /u/Fabulous_Adeptness_2
[link] [comments]
Can Android phones be hacked by calling
First of all I am from India and today I received a suspicious call that lasted 19 sec.
After I picked up the call no one talked to me for about 10 sec, just when I was about to hang up someone said that they are calling from Bajaj finance and if I wanted a loan, as soon as I said no they themselves hung up the call.
All this looks pretty suspicious to me so I thought any expert on the matter could help because one thing is for sure that it wasn't a call from customer service. Also my phones location was turned off.
submitted by /u/Fabulous_Adeptness_2
[link] [comments]
reddit
Can Android phones be hacked by calling
First of all I am from India and today I received a suspicious call that lasted 19 sec. After I picked up the call no one talked to me for about...
hacking: security in practice
I know that hackers can access celebrity private pictures even after they’ve been deleted for some months, but is there a timeline where that data eventually expires?
With years later, will those backed up copies just sitting in the cloud just stay there? Or will they expire? I’m simply just curious.
submitted by /u/lavagirl2345
[link] [comments]
I know that hackers can access celebrity private pictures even after they’ve been deleted for some months, but is there a timeline where that data eventually expires?
With years later, will those backed up copies just sitting in the cloud just stay there? Or will they expire? I’m simply just curious.
submitted by /u/lavagirl2345
[link] [comments]
reddit
I know that hackers can access celebrity private pictures even...
With years later, will those backed up copies just sitting in the cloud just stay there? Or will they expire? I’m simply just curious.
Hacking on Medium
Matryoshka doll(PicoCTF)
https://cdn-images-1.medium.com/max/1603/1*m-trKdp5c97NWZ9OPm8oDw.png
Note:- The flag you have to find on your own. This will just tell you the approach.
Continue reading on Medium »
Matryoshka doll(PicoCTF)
https://cdn-images-1.medium.com/max/1603/1*m-trKdp5c97NWZ9OPm8oDw.png
Note:- The flag you have to find on your own. This will just tell you the approach.
Continue reading on Medium »
Medium
Matryoshka doll(PicoCTF)
Note:- The flag you have to find on your own. This will just tell you the approach.
Hacking on Medium
How 1 Hacker Saved Coinbase and the Cryptocurrency Market From Disaster
https://cdn-images-1.medium.com/max/1920/1*8JBCrDrng4Dtxvj6_muUgA.png
And why the Crypto Community looks after its own
Continue reading on Crypto Unchained »
How 1 Hacker Saved Coinbase and the Cryptocurrency Market From Disaster
https://cdn-images-1.medium.com/max/1920/1*8JBCrDrng4Dtxvj6_muUgA.png
And why the Crypto Community looks after its own
Continue reading on Crypto Unchained »
Medium
How 1 Hacker Saved Coinbase and the Cryptocurrency Market From Disaster
And why the Crypto Community looks after its own
hacking: security in practice
What are the differences between Kali Linux Installer and Kali Linux Everything?
what are the differences? Does Kali Linux Everything have more tools?
submitted by /u/DnD_Junichiro
[link] [comments]
What are the differences between Kali Linux Installer and Kali Linux Everything?
what are the differences? Does Kali Linux Everything have more tools?
submitted by /u/DnD_Junichiro
[link] [comments]
reddit
What are the differences between Kali Linux Installer and Kali...
what are the differences? Does Kali Linux Everything have more tools?
hacking: security in practice
Hi guys and gals, would you recommend Kali or Parrot?
I’m working for a consulting company in cybersecurity and digital protection, but I want to shift to pentesting. I’m a noob but I’m learning with vulnhub, thm etc. I have both distros on my vm and I’m personally feeling good with Parrot, yet I’ve noticed that Kali is like the industry standard. Any recommendations on why one is better than the other?
submitted by /u/Swedish_Massacre
[link] [comments]
Hi guys and gals, would you recommend Kali or Parrot?
I’m working for a consulting company in cybersecurity and digital protection, but I want to shift to pentesting. I’m a noob but I’m learning with vulnhub, thm etc. I have both distros on my vm and I’m personally feeling good with Parrot, yet I’ve noticed that Kali is like the industry standard. Any recommendations on why one is better than the other?
submitted by /u/Swedish_Massacre
[link] [comments]
reddit
Hi guys and gals, would you recommend Kali or Parrot?
I’m working for a consulting company in cybersecurity and digital protection, but I want to shift to pentesting. I’m a noob but I’m learning with...
hacking: security in practice
Files from secured-work laptop to personal email/drive
Hey guys - I work at a consulting firm and I am about to leave and join a competitor.
Issues: 1. My laptop is secured and I can’t put a USB drive to upload some of the files I need to take with me.
1. The emails are monitored and I can’t sent anything without questions.
Any solutions to this?
Any help would be appreciated 😇
submitted by /u/kyennadiou
[link] [comments]
Files from secured-work laptop to personal email/drive
Hey guys - I work at a consulting firm and I am about to leave and join a competitor.
Issues: 1. My laptop is secured and I can’t put a USB drive to upload some of the files I need to take with me.
1. The emails are monitored and I can’t sent anything without questions.
Any solutions to this?
Any help would be appreciated 😇
submitted by /u/kyennadiou
[link] [comments]
reddit
Files from secured-work laptop to personal email/drive
Hey guys - I work at a consulting firm and I am about to leave and join a competitor. Issues: 1. My laptop is secured and I can’t put a USB drive...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Talisman - By Hooking Into The Pre-Push Hook Provided By Git, Talisman Validates The Outgoing Changeset For Things That Look Suspicious
http://www.kitploit.com/2022/02/talisman-by-hooking-into-pre-push-hook.html
http://www.kitploit.com/2022/02/talisman-by-hooking-into-pre-push-hook.html
A tool to detect and prevent secrets from getting checked in
What is Talisman? Talisman is a tool that installs a hook to your repository to ensure that potential secrets or sensitive information (https://www.kitploit.com/search/label/Sensitive%20Information) do not leave the developer's workstation. It validates the outgoing changeset for things that look suspicious - such as potential SSH keys, authorization (https://www.kitploit.com/search/label/Authorization) tokens, private keys etc.
Installation Talisman supports MAC OSX, Linux and Windows. Talisman can be installed and used in one of the following ways: As a git hook as a global git hook template (https://git-scm.com/docs/git-init#_template_directory) and a CLI utility (for git repo scanning) As a git hook into a single git repository Talisman can be set up as either a pre-commit or pre-push hook on the git repositories. Find the instructions below. Disclaimer: Secrets creeping in via a forced push in a git repository cannot be detected by Talisman. A forced push is believed to be notorious in its own ways, and we suggest git repository admins to apply appropriate measures to authorize such activities. [Recommended approach] Installation as a global hook template We recommend installing Talisman as a pre-commit git hook template, as that will cause Talisman to be present, not only in your existing git repositories, but also in any new repository that you 'init' or 'clone'. Run the following command on your terminal, to download and install the binary at $HOME/.talisman/bin As a pre-commit hook: curl --silent https://raw.githubusercontent.com/thoughtworks/talisman/master/global_install_scripts/install.bash > /tmp/install_talisman.bash && /bin/bash /tmp/install_talisman.bash
OR As a pre-push hook: curl --silent https://raw.githubusercontent.com/thoughtworks/talisman/master/global_install_scripts/install.bash > /tmp/install_talisman.bash && /bin/bash /tmp/install_talisman.bash pre-push
If you do not have TALISMAN_HOME set up in your $PATH, you will be asked an appropriate place to set it up. Choose the option number where you set the profile source on your machine. Remember to execute source on the path file or restart your terminal. If you choose to set the $PATH later, please export TALISMAN_HOME=$HOME/.talisman/bin to the path. Choose a base directory where Talisman should scan for all git repositories, and setup a git hook (pre-commit or pre-push, as chosen in step 1) as a symlink. This script will not clobber pre-existing hooks. If you have existing hooks, look for ways to chain Talisman into them. (https://github.com/thoughtworks/talisman#handling-existing-hooks) Handling existing hooks Installation of Talisman globally does not clobber pre-existing hooks on repositories.
If the installation script finds any existing hooks, it will only indicate so on the console.
To achieve running multiple hooks we suggest (but not limited to) the following two tools 1. Pre-commit (Linux/Unix) Use pre-commit (https://pre-commit.com/) tool to manage all the existing hooks along with Talisman. In the suggestion, it will prompt the following code to be included in .pre-commit-config.yaml - repo: local
hooks:
- id: talisman-precommit
name: talisman
entry: bash -c 'if [ -n "${TALISMAN_HOME:-}" ]; then ${TALISMAN_HOME}/talisman_hook_script pre-commit; else echo "TALISMAN does not exist. Consider installing from https://github.com/thoughtworks/talisman . If you already have talisman installed, please ensure TALISMAN_HOME variable is set to where talisman_hook_script resides, for example, TALISMAN_HOME=${HOME}/.talisman/bin"; fi'
language: system
pass_filenames: false
types: [text]
verbose: true
What is Talisman? Talisman is a tool that installs a hook to your repository to ensure that potential secrets or sensitive information (https://www.kitploit.com/search/label/Sensitive%20Information) do not leave the developer's workstation. It validates the outgoing changeset for things that look suspicious - such as potential SSH keys, authorization (https://www.kitploit.com/search/label/Authorization) tokens, private keys etc.
Installation Talisman supports MAC OSX, Linux and Windows. Talisman can be installed and used in one of the following ways: As a git hook as a global git hook template (https://git-scm.com/docs/git-init#_template_directory) and a CLI utility (for git repo scanning) As a git hook into a single git repository Talisman can be set up as either a pre-commit or pre-push hook on the git repositories. Find the instructions below. Disclaimer: Secrets creeping in via a forced push in a git repository cannot be detected by Talisman. A forced push is believed to be notorious in its own ways, and we suggest git repository admins to apply appropriate measures to authorize such activities. [Recommended approach] Installation as a global hook template We recommend installing Talisman as a pre-commit git hook template, as that will cause Talisman to be present, not only in your existing git repositories, but also in any new repository that you 'init' or 'clone'. Run the following command on your terminal, to download and install the binary at $HOME/.talisman/bin As a pre-commit hook: curl --silent https://raw.githubusercontent.com/thoughtworks/talisman/master/global_install_scripts/install.bash > /tmp/install_talisman.bash && /bin/bash /tmp/install_talisman.bash
OR As a pre-push hook: curl --silent https://raw.githubusercontent.com/thoughtworks/talisman/master/global_install_scripts/install.bash > /tmp/install_talisman.bash && /bin/bash /tmp/install_talisman.bash pre-push
If you do not have TALISMAN_HOME set up in your $PATH, you will be asked an appropriate place to set it up. Choose the option number where you set the profile source on your machine. Remember to execute source on the path file or restart your terminal. If you choose to set the $PATH later, please export TALISMAN_HOME=$HOME/.talisman/bin to the path. Choose a base directory where Talisman should scan for all git repositories, and setup a git hook (pre-commit or pre-push, as chosen in step 1) as a symlink. This script will not clobber pre-existing hooks. If you have existing hooks, look for ways to chain Talisman into them. (https://github.com/thoughtworks/talisman#handling-existing-hooks) Handling existing hooks Installation of Talisman globally does not clobber pre-existing hooks on repositories.
If the installation script finds any existing hooks, it will only indicate so on the console.
To achieve running multiple hooks we suggest (but not limited to) the following two tools 1. Pre-commit (Linux/Unix) Use pre-commit (https://pre-commit.com/) tool to manage all the existing hooks along with Talisman. In the suggestion, it will prompt the following code to be included in .pre-commit-config.yaml - repo: local
hooks:
- id: talisman-precommit
name: talisman
entry: bash -c 'if [ -n "${TALISMAN_HOME:-}" ]; then ${TALISMAN_HOME}/talisman_hook_script pre-commit; else echo "TALISMAN does not exist. Consider installing from https://github.com/thoughtworks/talisman . If you already have talisman installed, please ensure TALISMAN_HOME variable is set to where talisman_hook_script resides, for example, TALISMAN_HOME=${HOME}/.talisman/bin"; fi'
language: system
pass_filenames: false
types: [text]
verbose: true
2. Husky (Linux/Unix/Windows) husky (https://github.com/typicode/husky/blob/master/DOCS.md) is an npm module for managing git hooks. In order to use husky, make sure you have already set TALISMAN_HOME to $PATH. Existing Users If you already are using husky, add the following lines to husky pre-commit in package.json Windows "bash -c '\"%TALISMAN_HOME%\\${TALISMAN_BINARY_NAME}\" --githook pre-commit'"
Linux/Unix $TALISMAN_HOME/talisman_hook_script pre-commit
New Users If you want to use husky with multiple hooks along with talisman, add the following snippet to you package json. Windows {
"husky": {
"hooks": {
"pre-commit": "bash -c '\"%TALISMAN_HOME%\\${TALISMAN_BINARY_NAME}\" --githook pre-commit'" && "other-scripts"
}
}
}
Linux/Unix {
"husky": {
"hooks": {
"pre-commit": "$TALISMAN_HOME/talisman_hook_script pre-commit" && "other-scripts"
}
}
}
Installation to a single project ~/install-talisman.sh chmod +x ~/install-talisman.sh"># Download the talisman installer script
curl https://thoughtworks.github.io/talisman/install.sh > ~/install-talisman.sh
chmod +x ~/install-talisman.sh # Install to a single project
cd my-git-project
# as a pre-push hook
~/install-talisman.sh
# or as a pre-commit hook
~/install-talisman.sh pre-commit Handling existing hooks Talisman will need to be chained with any existing git hooks.You can use pre-commit (https://pre-commit.com/) git hooks framework to handle this. Add this to your .pre-commit-config.yaml (be sure to update rev to point to a real git revision!) - repo: https://github.com/thoughtworks/talisman
rev: '' # Update me!
hooks:
# either `commit` or `push` support
- id: talisman-commit
# - id: talisman-push Disclaimer: Talisman cannot guarantee its functionality in MicroSoft's unsupported versions of Windows. Anyway Taliman is successfully tested on Windows 7 and server 2008 R2, which might not work in future releases. Upgrading Since release v0.4.4, Talisman automatically updates the binary to the latest release, when the hook is invoked (at pre-commit/pre-push, as set up). So, just sit back, relax, and keep using the latest Talisman without any extra efforts. The following environment variables can be set: TALISMAN_SKIP_UPGRADE: Set to true if you want to skip the automatic upgrade check. Default is false TALISMAN_UPGRADE_CONNECT_TIMEOUT: Max connect timeout before the upgrade is cancelled(in seconds). Default is 10 seconds. If at all you need to manually upgrade, here are the steps:
[Recommended] Update Talisman binary and hook scripts to the latest release: curl --silent https://raw.githubusercontent.com/thoughtworks/talisman/master/global_install_scripts/update_talisman.bash > /tmp/update_talisman.bash && /bin/bash /tmp/update_talisman.bash Update only Talisman binary by executing: curl --silent https://raw.githubusercontent.com/thoughtworks/talisman/master/global_install_scripts/update_talisman.bash > /tmp/update_talisman.bash && /bin/bash /tmp/update_talisman.bash talisman-binary Talisman in action After the installation is successful, Talisman will run checks for obvious secrets automatically before each commit or push (as chosen during installation). In case there are any security breaches detected, talisman will display a detailed report of the errors: $ git push
Talisman Report:
+-----------------+-------------------------------------------------------------------------------+
| FILE | ERRORS |
+-----------------+-------------------------------------------------------------------------------+
| danger.pem | The file name "danger.pem" |
| | failed checks against the |
Linux/Unix $TALISMAN_HOME/talisman_hook_script pre-commit
New Users If you want to use husky with multiple hooks along with talisman, add the following snippet to you package json. Windows {
"husky": {
"hooks": {
"pre-commit": "bash -c '\"%TALISMAN_HOME%\\${TALISMAN_BINARY_NAME}\" --githook pre-commit'" && "other-scripts"
}
}
}
Linux/Unix {
"husky": {
"hooks": {
"pre-commit": "$TALISMAN_HOME/talisman_hook_script pre-commit" && "other-scripts"
}
}
}
Installation to a single project ~/install-talisman.sh chmod +x ~/install-talisman.sh"># Download the talisman installer script
curl https://thoughtworks.github.io/talisman/install.sh > ~/install-talisman.sh
chmod +x ~/install-talisman.sh # Install to a single project
cd my-git-project
# as a pre-push hook
~/install-talisman.sh
# or as a pre-commit hook
~/install-talisman.sh pre-commit Handling existing hooks Talisman will need to be chained with any existing git hooks.You can use pre-commit (https://pre-commit.com/) git hooks framework to handle this. Add this to your .pre-commit-config.yaml (be sure to update rev to point to a real git revision!) - repo: https://github.com/thoughtworks/talisman
rev: '' # Update me!
hooks:
# either `commit` or `push` support
- id: talisman-commit
# - id: talisman-push Disclaimer: Talisman cannot guarantee its functionality in MicroSoft's unsupported versions of Windows. Anyway Taliman is successfully tested on Windows 7 and server 2008 R2, which might not work in future releases. Upgrading Since release v0.4.4, Talisman automatically updates the binary to the latest release, when the hook is invoked (at pre-commit/pre-push, as set up). So, just sit back, relax, and keep using the latest Talisman without any extra efforts. The following environment variables can be set: TALISMAN_SKIP_UPGRADE: Set to true if you want to skip the automatic upgrade check. Default is false TALISMAN_UPGRADE_CONNECT_TIMEOUT: Max connect timeout before the upgrade is cancelled(in seconds). Default is 10 seconds. If at all you need to manually upgrade, here are the steps:
[Recommended] Update Talisman binary and hook scripts to the latest release: curl --silent https://raw.githubusercontent.com/thoughtworks/talisman/master/global_install_scripts/update_talisman.bash > /tmp/update_talisman.bash && /bin/bash /tmp/update_talisman.bash Update only Talisman binary by executing: curl --silent https://raw.githubusercontent.com/thoughtworks/talisman/master/global_install_scripts/update_talisman.bash > /tmp/update_talisman.bash && /bin/bash /tmp/update_talisman.bash talisman-binary Talisman in action After the installation is successful, Talisman will run checks for obvious secrets automatically before each commit or push (as chosen during installation). In case there are any security breaches detected, talisman will display a detailed report of the errors: $ git push
Talisman Report:
+-----------------+-------------------------------------------------------------------------------+
| FILE | ERRORS |
+-----------------+-------------------------------------------------------------------------------+
| danger.pem | The file name "danger.pem" |
| | failed checks against the |
| | awsSecretKey=c64e8c79aacf5ddb02f1274db2d973f363f4f553ab1692d8d203b4cc09692f79 |
+-----------------+-------------------------------------------------------------------------------+ In the above example, the file danger.pem has been flagged as a security breach due to the following reasons: The filename matches one of the pre-configured patterns. The file contains an awsSecretKey which is scanned and flagged by Talisman If you have installed Talisman as a pre-commit hook, it will scan only the diff within each commit. This means that it would only report errors for parts of the file that were changed. In case you have installed Talisman as a pre-push hook, it will scan the complete file in which changes are made. As mentioned above, it is recommended that you use Talisman as a pre-commit hook. Validations The following detectors execute against the changesets to detect secrets/sensitive information: Encoded values - scans for encoded secrets in Base64, hex etc. File content - scans for suspicious content in file that could be potential secrets or passwords File size - scans for large files that may potentially contain keys or other secrets Entropy - scans for content with high entropy that are likely to contain passwords Credit card numbers - scans for content that could be potential credit card numbers File names - scans for file names and extensions that could indicate them potentially containing secrets, such as keys, credentials (https://www.kitploit.com/search/label/Credentials) etc. Ignoring Files If you're really sure you want to push that file, you can configure it into the .talismanrc file in the project root. The contents required for ignoring your failed files will be printed by Talisman on the console immediately after the Talisman Error Report: If you are absolutely sure that you want to ignore the above files from talisman detectors, consider pasting the following format in .talismanrc file in the project root
fileignoreconfig:
- filename: danger.pem
checksum: cf97abd34cebe895417eb4d97fbd7374aa138dcb65b1fe7f6b6cc1238aaf4d48
ignore_detectors: [] Entering this in the .talismanrc file will ensure that Talisman will ignore the danger.pem file as long as the checksum matches the value mentioned in the checksum field. Interactive mode Available only for non-Windows users If it is too much of a hassle to keep copying content to .talismanrc everytime you encounter an error from Talisman, you could enable the interactive mode and let Talisman assist you in prompting the additions of the files to ignore. Just follow the simple steps: Open your bash profile where your environment variables are set (.bashrc, .bash_profile, .profile or any other location) You will see TALISMAN_INTERACTIVE variable under # >>> talisman >>> If not already set to true, add export TALISMAN_INTERACTIVE=true Don't forget to save and source the file That's it! Every time Talisman hook finds an error during pre-push/pre-commit, just follow the instructions as Talisman suggests. Be careful to not ignore a file without verifying the content. You must be confident that no secret is getting leaked out. Ignoring specific detectors Below is a detailed description of the various fields that can be configured into the .talismanrc file: filename : This field should mention the fully qualified filename. checksum : This field should always have the value specified by Talisman in the message displayed above. If at any point, a new change is made to the file, it will result in a new checksum and Talisman will scan the file again for any potential security threats. ignore_detectors : This field will disable specific detectors for a particular file. For example, if your init-env.sh filename triggers a warning, you can only disable this warning while still being alerted if other things go wrong (e.g. file content): fileignoreconfig:
- filename: init-env.sh
+-----------------+-------------------------------------------------------------------------------+ In the above example, the file danger.pem has been flagged as a security breach due to the following reasons: The filename matches one of the pre-configured patterns. The file contains an awsSecretKey which is scanned and flagged by Talisman If you have installed Talisman as a pre-commit hook, it will scan only the diff within each commit. This means that it would only report errors for parts of the file that were changed. In case you have installed Talisman as a pre-push hook, it will scan the complete file in which changes are made. As mentioned above, it is recommended that you use Talisman as a pre-commit hook. Validations The following detectors execute against the changesets to detect secrets/sensitive information: Encoded values - scans for encoded secrets in Base64, hex etc. File content - scans for suspicious content in file that could be potential secrets or passwords File size - scans for large files that may potentially contain keys or other secrets Entropy - scans for content with high entropy that are likely to contain passwords Credit card numbers - scans for content that could be potential credit card numbers File names - scans for file names and extensions that could indicate them potentially containing secrets, such as keys, credentials (https://www.kitploit.com/search/label/Credentials) etc. Ignoring Files If you're really sure you want to push that file, you can configure it into the .talismanrc file in the project root. The contents required for ignoring your failed files will be printed by Talisman on the console immediately after the Talisman Error Report: If you are absolutely sure that you want to ignore the above files from talisman detectors, consider pasting the following format in .talismanrc file in the project root
fileignoreconfig:
- filename: danger.pem
checksum: cf97abd34cebe895417eb4d97fbd7374aa138dcb65b1fe7f6b6cc1238aaf4d48
ignore_detectors: [] Entering this in the .talismanrc file will ensure that Talisman will ignore the danger.pem file as long as the checksum matches the value mentioned in the checksum field. Interactive mode Available only for non-Windows users If it is too much of a hassle to keep copying content to .talismanrc everytime you encounter an error from Talisman, you could enable the interactive mode and let Talisman assist you in prompting the additions of the files to ignore. Just follow the simple steps: Open your bash profile where your environment variables are set (.bashrc, .bash_profile, .profile or any other location) You will see TALISMAN_INTERACTIVE variable under # >>> talisman >>> If not already set to true, add export TALISMAN_INTERACTIVE=true Don't forget to save and source the file That's it! Every time Talisman hook finds an error during pre-push/pre-commit, just follow the instructions as Talisman suggests. Be careful to not ignore a file without verifying the content. You must be confident that no secret is getting leaked out. Ignoring specific detectors Below is a detailed description of the various fields that can be configured into the .talismanrc file: filename : This field should mention the fully qualified filename. checksum : This field should always have the value specified by Talisman in the message displayed above. If at any point, a new change is made to the file, it will result in a new checksum and Talisman will scan the file again for any potential security threats. ignore_detectors : This field will disable specific detectors for a particular file. For example, if your init-env.sh filename triggers a warning, you can only disable this warning while still being alerted if other things go wrong (e.g. file content): fileignoreconfig:
- filename: init-env.sh
export AWS_ACCESS_KEY_ID=$(vault read -field=value path/to/aws-access-key-id) By default, Talisman will alert for both lines. In the second line, we are extracting the AWS Access Key ID from Hashicorp Vault which doesn't expose the secret to the code. If this type of usage is common in your code, you might want to tell Talisman to not alert when you use a Vault. This can be achieved with a configuration like: allowed_patterns:
- export\ AWS[ \w]*KEY[ \w]*=.*vault\ read.* Ignoring multiple files of same type (with wildcards) You can choose to ignore all files of a certain type, because you know they will always be safe, and you wouldn't want Talisman to scan them. Steps: Format a wildcard pattern for the files you want to ignore. For example, *.lock Use the checksum calculator (https://github.com/thoughtworks/talisman#checksum-calculator) to feed the pattern and attain a collective checksum. For example, talisman --checksum="*.lock" Copy the fileconfig block, printed on console, to .talismanrc file. If any of the files are modified, talisman will scan the files again, unless you re-calculate the new checksum and replace it in .talismanrc file. Ignoring files by specifying language scope You can choose to ignore files by specifying the language scope for your project in your talismanrc. scopeconfig:
- scope: go
- scope: node
- scope: images Talisman is configured to ignore certain files based on the specified scope. For example, mentioning the node scope in the scopeconfig will prevent talisman from scanning files such as the yarn.lock or package-lock.json. You can specify multiple scopes. Currently .talismanrc only supports scopeconfig support for go, node and images. Other scopes will be added shortly. Custom search patterns You can specify custom regex patterns to look for in the current repository custom_patterns:
- pattern1
- pattern2
Note: The use of .talismanignore has been deprecated. File .talismanrc replaces it because: .talismanrc has a much more legible yaml format It also brings in more secure practices with every modification (https://www.kitploit.com/search/label/Modification) of a file with a potential sensitive value to be reviewed The new format also brings in the extensibility to introduce new usable functionalities. Keep a watch out for more Configuring severity threshold Each validation is associated with a severity Low Medium High You can specify a threshold in your .talismanrc: threshold: medium This will report all Medium severity issues and higher (Potential risks that are below the threshold will be reported in the warnings) A list of all risks with their severity level can be found in this configuration file (https://github.com/thoughtworks/talisman/blob/master/detector/severity/severity_config.go). By default, the threshold is set to low. Any custom search patterns you add, are considered to be of high severity. Configuring custom severities You can customize the security levels (https://github.com/thoughtworks/talisman/blob/master/detector/severity/severity_config.go) of the detectors provided by Talisman in the .talismanrc file: custom_severities:
- detector: Base64Content
severity: medium
- detector: HexContent
severity: low By using custom severities and a severity threshold, Talisman can be configured to alert only on what is important based on your context. This can be useful to reduce the number of false positives. Talisman as a CLI utility If you execute talisman on the command line, you will be able to view all the parameter options you can pass -c, --checksum string checksum calculator calculates checksum and suggests .talismanrc format
-d, --debug enable debug mode (warning: very verbose)
-g, --githook string either pre-push or pre-commit (default "pre-push")
--ignoreHistory scanner scans all files on current head, will not scan through git commit history
- export\ AWS[ \w]*KEY[ \w]*=.*vault\ read.* Ignoring multiple files of same type (with wildcards) You can choose to ignore all files of a certain type, because you know they will always be safe, and you wouldn't want Talisman to scan them. Steps: Format a wildcard pattern for the files you want to ignore. For example, *.lock Use the checksum calculator (https://github.com/thoughtworks/talisman#checksum-calculator) to feed the pattern and attain a collective checksum. For example, talisman --checksum="*.lock" Copy the fileconfig block, printed on console, to .talismanrc file. If any of the files are modified, talisman will scan the files again, unless you re-calculate the new checksum and replace it in .talismanrc file. Ignoring files by specifying language scope You can choose to ignore files by specifying the language scope for your project in your talismanrc. scopeconfig:
- scope: go
- scope: node
- scope: images Talisman is configured to ignore certain files based on the specified scope. For example, mentioning the node scope in the scopeconfig will prevent talisman from scanning files such as the yarn.lock or package-lock.json. You can specify multiple scopes. Currently .talismanrc only supports scopeconfig support for go, node and images. Other scopes will be added shortly. Custom search patterns You can specify custom regex patterns to look for in the current repository custom_patterns:
- pattern1
- pattern2
Note: The use of .talismanignore has been deprecated. File .talismanrc replaces it because: .talismanrc has a much more legible yaml format It also brings in more secure practices with every modification (https://www.kitploit.com/search/label/Modification) of a file with a potential sensitive value to be reviewed The new format also brings in the extensibility to introduce new usable functionalities. Keep a watch out for more Configuring severity threshold Each validation is associated with a severity Low Medium High You can specify a threshold in your .talismanrc: threshold: medium This will report all Medium severity issues and higher (Potential risks that are below the threshold will be reported in the warnings) A list of all risks with their severity level can be found in this configuration file (https://github.com/thoughtworks/talisman/blob/master/detector/severity/severity_config.go). By default, the threshold is set to low. Any custom search patterns you add, are considered to be of high severity. Configuring custom severities You can customize the security levels (https://github.com/thoughtworks/talisman/blob/master/detector/severity/severity_config.go) of the detectors provided by Talisman in the .talismanrc file: custom_severities:
- detector: Base64Content
severity: medium
- detector: HexContent
severity: low By using custom severities and a severity threshold, Talisman can be configured to alert only on what is important based on your context. This can be useful to reduce the number of false positives. Talisman as a CLI utility If you execute talisman on the command line, you will be able to view all the parameter options you can pass -c, --checksum string checksum calculator calculates checksum and suggests .talismanrc format
-d, --debug enable debug mode (warning: very verbose)
-g, --githook string either pre-push or pre-commit (default "pre-push")
--ignoreHistory scanner scans all files on current head, will not scan through git commit history