Attacking Development Pipelines for Actual Profit

Attacking Development Pipelines for Actual Profit

44CON Information Security Conference via YouTube Direct link

Introduction

1 of 16

1 of 16

Introduction

Class Central Classrooms beta

YouTube playlists curated by Class Central.

Classroom Contents

Attacking Development Pipelines for Actual Profit

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Introduction
  2. 2 CI/CD Pipelines?
  3. 3 CI/CD: Command Execution as a Service
  4. 4 Methodology - Definition
  5. 5 IRL Issue: Perforce
  6. 6 IRL Issue: Network Storage
  7. 7 Methodology - Execution
  8. 8 Tooling - SSHReverse Shell
  9. 9 IRL Issue: Cross Instance Compromise
  10. 10 Methodology - Secret Management
  11. 11 IRL Issue: VMware guestinfo variables
  12. 12 Methodology - Reports
  13. 13 Tooling - Research Servers
  14. 14 IRL Issue: Web Hook - Classic DNS Rebinding
  15. 15 Methodology - Deployment
  16. 16 Summary

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.