3 ms·
I actually really like that idea, constantly scanning logs for hyper-specific red flags. I might start doing this.
by MartinCron 7y ago
I actually really like that idea, constantly scanning logs for hyper-specific red flags. I might start doing this.
- londons_explore 7y agoI do this already, for both user passwords, but also accidental leaking of internal company data into logfiles. It also checks for base64 encoded versions of the data (with various alignments). There is also an alert if data is unscannable (due to compression or encryption). The check is done at logs ingestion points, but also on outgoing http requests from webdriver automated tests (since some third party scripts might be shipping the data off to someone else's server). The scanned for words are: * the top 100 passwords, excluding things used as test strings. * A few company specific passwords. * A few testing passwords * A few random strings which are also deliberately inserted into source code files in places that should never (by design) pass between client and server.
- MartinCron 7y agoThanks so much for sharing.