5 ms·
I am surprised that there is no automated alert to tell the webmaster that his code has changed on his website. Especially on the payments page! With 50,000,00
by gregpilling 8y ago
I am surprised that there is no automated alert to tell the webmaster that his code has changed on his website. Especially on the payments page!
With 50,000,000 users a month, surely they have a whole team working on checkout, all the time?
- ryanlol 8y agoDo you have such automated alerts set up yourself? Do you know anyone with such alerts set up?
- freddie_mercury 8y agoWhenever someone complains about another company's product, code, features, security....I always wish it was mandatory to include a link to the kind of software the poster is putting into production. I can dream. Glass houses and all that.
- elorant 8y agoI have. I deploy in ASP.NET and get a hash of the uploaded DLL. I check it twice a day. Never had any incidents to this day but as the saying goes, it's better to be safe than sorry.
- tedunangst 8y agoAnd how does the hash of the DLL on some server relate to the content seen by users?
- ixwt 8y agoI would assume the DLL is responsible for the output of the content seen by users.
- elorant 8y agoIn ASP.NET pretty much all output, including html and js is included in the DLL. Only external js files are left out. Sure they could hack them which means my solution isn't bulletproof but I could also produce a hash for them too.
- reaperducer 8y agoI do. I have a tiny $5 Onion Omega2 on an independent cellular connection that checks file integrity on the production web servers every 15 minutes. If the content of any of the files change, I get an e-mail. If the alerts start coming in when I know I've just pushed a new version to production, the mail has a link that I can click that will re-scan all of the files and build new checksums. If the alerts start coming in in the middle of the night, then I know something is up. Obviously, this only works in small environments like mine where I'm the only one capable of updating the production servers. But it managed to catch a backdoor left in by the previous developer, who for some reason stored and updated his resume on the production server.
- noir_lord 8y agoIngenious, Have you considered a blog post on this approach? It would be interesting to deploy a few of them in different places and check that they all see the same as well maybe. Also did you do this as a belts and braces thing or is the system you are auditing particularly high security/risk in some way?
- ams6110 8y agoYou can just set up Tripwire to do this sort of thing. It's in most distro package managers. https://github.com/Tripwire/tripwire-open-source/#open-source-tripwire https://github.com/Tripwire/tripwire-open-source/#open-sourc... What that won't do is save you from malicious code inserted into 3rd party content (script libraries, etc.) that you load from a CDN. If you're worried about that, you should make a copy of a verified version and serve it yourself.
- reaperducer 8y agoYou can just set up Tripwire to do this sort of thing I wanted something that was completely independent of the machine. Separate box, separate network, separate architecture, etc... What that won't do is save you from malicious code inserted into 3rd party content (script libraries, etc.) that you load from a CDN. If you're worried about that, you should make a copy of a verified version and serve it yourself. I don't CDN on work projects. It's not worth the risk. If something goes wrong, I'd rather it be my fault and something I can understand and fix, whenever possible. Farming stuff out just leads to layers of things that can break, be compromised, or simply go wrong. Again, it works at my scale (about 15 sites). It won't work for everyone.
- lacker 8y agoCode is supposed to change on the website all the time, though, when they run a deploy. Surely they do have a team working on checkout, but it isn't obvious how this would be detected. The article leaves out how they got the malicious javascript onto the page in the first place, though, so it's hard to say.