Earlier quoted context omitted.
0 times out of ten for me. First I blocked the annoying cat, then I got to the bottom, was assaulted by blinking buttons and decided I didn’t need to know what else they were saying anyway.
Have you tried Firefox Reader Mode? It renders this website (and a lot of others) without a lot of distractions.
Infosec company pwned by 4chan user
211–220 of 234 posts
Re: Infosec company pwned by 4chan user
#212Earlier quoted context omitted.
The most horrible thing Jenkins does to devs is it encourages bad practice. Good practice is so cumbersome to do properly (create a secret, load secret in env through Groovy code, setup git configuration in a shell script) that, unless someone is actively monitoring them, devs are always in a temptation to just put the credentials in the git URL, we'll remove them after testing . Then one out of N times they forget a…
Uh, no, you just pick credentials from list in the repo config. If you wanted to download additional repo in the jenkins script sure, but Jenkins Git plugin just accepts credential (whether its password or pub/priv key pair), just paste URL and select one from the list
That said, I doubt that what happened here was a Jenkins configuration problem, and instead something to do with the build scripts they're running on Jenkins. You can't solve every class of stupid, sadly.
Re: Infosec company pwned by 4chan user
#213Earlier quoted context omitted.
..written in Java. In case anyone needs reminding, Java developers, on purpose, put a line in a logging library that can fetch and execute code when given a url string for a log statement. Nobody should be touching anything Java in 2023.
Yes, we all sat down and unanimously agreed that we should perform JNDI lookups to execute arbitrary code stored in an LDAP directory. No regrets.
Re: Infosec company pwned by 4chan user
#214"however, they made one of the most comedic mistakes you can still make while setting up jenkins (im actually not sure which misconfiguration leads to this): the build information for each past build contains a link to the git repository, including the bitbucket credentials in the url. genius."
The most horrible thing Jenkins does to devs is it encourages bad practice. Good practice is so cumbersome to do properly (create a secret, load secret in env through Groovy code, setup git configuration in a shell script) that, unless someone is actively monitoring them, devs are always in a temptation to just put the credentials in the git URL, we'll remove them after testing . Then one out of N times they forget a…
Re: Infosec company pwned by 4chan user
#215I always tell myself, if I ever start any kind of business, I’ll make sure to host my website as static content on a read only file system. And customer data will be handled by 3rd party
Re: Infosec company pwned by 4chan user
#216Earlier quoted context omitted.
A quick glance to the history of the article, I see it was edited by multiple usernames and IP address at different times. How did you come to the conclusion that it was self authored?
Because this is a person that doesn't meet the notoriety requirements for Wikipedia, and goes into a level of detail that is also totally unnecessary. It is trivial to connect to different servers via VPN and creating new usernames on Wikipedia takes seconds.
Re: Infosec company pwned by 4chan user
#217Re: Infosec company pwned by 4chan user
#218Earlier quoted context omitted.
..written in Java. In case anyone needs reminding, Java developers, on purpose, put a line in a logging library that can fetch and execute code when given a url string for a log statement. Nobody should be touching anything Java in 2023.
Yes, we all sat down and unanimously agreed that we should perform JNDI lookups to execute arbitrary code stored in an LDAP directory. No regrets.
I honestly don't even blame the developers of Log4J that much, because after all its open source, and nobody is paying them to use it despite the idiocy surrounding shit like that.
I do however blame the developers that use Java, see things like this happen, and then continue to use it with Log4j after the patch like nothing ever happened.
Re: Infosec company pwned by 4chan user
#219Earlier quoted context omitted.
..written in Java. In case anyone needs reminding, Java developers, on purpose, put a line in a logging library that can fetch and execute code when given a url string for a log statement. Nobody should be touching anything Java in 2023.
Yes, we all sat down and unanimously agreed that we should perform JNDI lookups to execute arbitrary code stored in an LDAP directory. No regrets.
Re: Infosec company pwned by 4chan user
#220Earlier quoted context omitted.
1. post link to jenkins job in a 4chan thread relating to something nefarious 2. see who clicks it 3. now you have IP addresses of possibly nefarious people without needing to subpoena 4chan Something like that.
How to waste your time tracking down 20000 wanna be script kiddies?
It only takes a dozen people having money and fearing court for this to be profitable. The lawyer doesn't want to go to court because that costs money, he just wants you to confess and get paid.