Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
hackerpain
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
hackerpain
6y ago
Yes but how does that work? i have heard of unexploitable overflows how does that work? and hey: Your username tricked me.
32.
▲
Ask HN: How do buffer overflows still happen in spite of ASLR?
4 points
by
hackerpain
6y ago
|
3 comments
33.
▲
by
hackerpain
6y ago
It's not. They may have a private program, don't know.
34.
▲
by
hackerpain
6y ago
AWS now sends emails if you commit access keys, even better they are catching loads of other sensitive info having privileged access to the GitHub API. Cool and creepy at the same time, right?
35.
▲
by
hackerpain
6y ago
The researcher added there may be some certificates exposed in that repo which may have been used to sign the binaries. It's still a relevant update. Especially the information that the repo was archived by Web Archive back in 2018. It
36.
▲
by
hackerpain
6y ago
It's useful but yeah a ton of false positives :) Most common false positives appear to be the test values.
37.
▲
by
hackerpain
6y ago
There's some new information released which mentions the github repo name, and since when the vulnerability has existed.
38.
▲
by
hackerpain
6y ago
I have found a LARGE social media having a similar kind of vulnerability. Downloaded some data as Proof of concept. There's no way to reach their CEO and no security contact. How should I report it in your opinion?
39.
▲
by
hackerpain
6y ago
Not if you use TruffleHog and GitGuardian.
40.
▲
by
hackerpain
6y ago
wasn't even an SFTP I guess? good old FTP
41.
▲
by
hackerpain
6y ago
> We have been advised Their advisor was smart enough to call it so.
42.
▲
by
hackerpain
6y ago
The news and press defined the "attack sophistication". An attack of this scale definitely needs some amount of sophistication but on a difficulty scale of 1-10 to infiltrate their network, I would rate it a humble 0.5/10.
43.
▲
SolarWinds leaked FTP credentials through a public GitHub repo since 2018
(savebreach.com)
183 points
by
hackerpain
6y ago
|
92 comments
44.
▲
ShhGit – A tool to monitor sensitive secrets exposed via GitHub in real-time
(shhgit.com)
4 points
by
hackerpain
6y ago
|
0 comments
45.
▲
by
hackerpain
6y ago
The article has mentioned its purely based on speculation, it doesn't claim - it was the cause. There has to be a bigger chain of attacks that led to the breach.
46.
▲
by
hackerpain
6y ago
There was a case where we were able to gain access to Jira instance belonging to a bug bounty target (not even a Red Team engagement), and the Confluence wiki had every credential the company ever used. They used it as a secure credential s
47.
▲
by
hackerpain
6y ago
For basic live monitoring -- https://www.shhgit.com/ It's possible to monitor them while pushing code, and to have a monitoring system deployed to track them. I was thinking of open-sourcing our GitHubSniper tool, it b
48.
▲
SolarWinds exposed FTP credentials in Public Github Repo: US Government Breach
(savebreach.com)
142 points
by
hackerpain
6y ago
|
67 comments
49.
▲
iPhone Manufacturing company in India ransacked by workers, over $50mn USD lost
(businesstoday.in)
7 points
by
hackerpain
6y ago
|
0 comments
50.
▲
PayPal's confusing UI could be a threat to its users
(savebreach.com)
13 points
by
hackerpain
6y ago
|
0 comments
51.
▲
by
hackerpain
6y ago
Most no-code solutions are proprietary and it would be hard to optimize and maintain them. But it may work for smaller applications and mobile apps where you want to define a small set of feature.
52.
▲
I Hacked Google's Bug Tracker to Claim a Google.com Email Address
(andmp.com)
16 points
by
hackerpain
6y ago
|
0 comments
53.
▲
I Hacked into Facebook's Legal Department Admin Panel
(alaa.blog)
669 points
by
hackerpain
6y ago
|
290 comments
54.
▲
by
hackerpain
6y ago
Hey, Seems like the app isn't open source. But they are apparently having a Big Dataset of scraped Github content as GitHub API provides limited search operations with rate limiting. But here's the API -> https://gre
55.
▲
Grep.app, a GitHub code search engine to search for code patterns and examples
(grep.app)
4 points
by
hackerpain
6y ago
|
3 comments
56.
▲
by
hackerpain
6y ago
Seems really useful, there's another tool -- https://grep.app that searches for code patterns throughout GitHub, very useful to take inspiration from other's code or, look for examples.