Earlier quoted context omitted.
“Who still uses Jenkins?” I think you may have perhaps misjudged just how entrenched Jenkins is in corp/enterprise.
The older I get, the more systems I learn are only around because they've been around.
Infosec company pwned by 4chan user
111–120 of 234 posts
Re: Infosec company pwned by 4chan user
#112I had to check the article to understand how it is notable for a 4chan user to also be a business owner. They're using "owned" in leet speak sense, infiltrated security.
I too thought it would be about a company who was a sole proprietor of an infosec corp lol
Re: Infosec company pwned by 4chan user
#113Earlier quoted context omitted.
Is there an F/OSS alternative to Jenkins that I’m not aware of?
- Woodpecker CI: https://woodpecker-ci.org/ - Drone CI: https://www.drone.io/ - Buildbot: https://buildbot.net/ - Gitea Actions: https://docs.gitea.io/en-us/usage/actions/overview/ - Fogejo Actions: https://forgejo.org/2023-02-27-forgejo-actions/ - GitLab Runners: https://gitlab.com/gitlab-org/gitlab-runner You could also use Ansible playbooks/roles to run your build, although that's going to be a bit more manual: ht…
Re: Infosec company pwned by 4chan user
#114Earlier quoted context omitted.
But what's the trap here? Checking who downloads the file? I don't see how they can get any actionable info out of this
1. post link to jenkins job in a 4chan thread relating to something nefarious 2. see who clicks it 3. now you have IP addresses of possibly nefarious people without needing to subpoena 4chan Something like that.
ahahah 4chan is almost as mainstream as Reddit. ahahahahahahaaaaaaa you really think they would waste time like this for IP addresses to "keep track of"
Re: Infosec company pwned by 4chan user
#115> which makes it all so much more ironic how completely they have been hacked. Nope, not really. It just takes one mistake and you're pwned. Imagine giving the intern a small project, you're losing your head due to your main project, no time to supervise. Boom. /e: Or imagine an update in one of your libs/apps. In order to not to be hacked you need to make everything right. In order to hack you just need to find one…
Re: Infosec company pwned by 4chan user
#116Re: Infosec company pwned by 4chan user
#117Earlier quoted context omitted.
Appears to be self-authored.
A quick glance to the history of the article, I see it was edited by multiple usernames and IP address at different times. How did you come to the conclusion that it was self authored?
Re: Infosec company pwned by 4chan user
#118Earlier quoted context omitted.
The correct spelling in that case is pwned isn’t it? I got it from context, but those always felt like subtly different words to me.
I've seen owned plenty of times. "Owned a box" like that
Re: Infosec company pwned by 4chan user
#119Earlier quoted context omitted.
- Woodpecker CI: https://woodpecker-ci.org/ - Drone CI: https://www.drone.io/ - Buildbot: https://buildbot.net/ - Gitea Actions: https://docs.gitea.io/en-us/usage/actions/overview/ - Fogejo Actions: https://forgejo.org/2023-02-27-forgejo-actions/ - GitLab Runners: https://gitlab.com/gitlab-org/gitlab-runner You could also use Ansible playbooks/roles to run your build, although that's going to be a bit more manual: ht…
How did Apache Maven make it onto this list? Seems like Maven is a build tool that one would invoke _from_ Jenkins or Drone.
Re: Infosec company pwned by 4chan user
#120I had to check the article to understand how it is notable for a 4chan user to also be a business owner. They're using "owned" in leet speak sense, infiltrated security.
Man I was wondering the exactly same thing! I’m not a native speaker so that might be why