CI/CD GOAT: Mad Hatter Capture The Flag

Поділитися
Вставка
  • Опубліковано 19 гру 2024

КОМЕНТАРІ • 39

  • @ahmerkhan496
    @ahmerkhan496 Рік тому +40

    Man you are insane, I am working as a Devops Engineer and this has some unique insights, keep up the good work !

    • @Knightfall23
      @Knightfall23 Рік тому +2

      This was nothing more than someone just running printenv within a script.
      If your a devops engineer you should know about the Solar Winds hacks that happened a few years ago, those were the real CI/CD and supply chain poisoning tactics.

    • @quickkcare605
      @quickkcare605 Рік тому +2

      @@Knightfall23 Yeah you are right bro. That guy must be an intern

    • @endoflevelboss
      @endoflevelboss Рік тому

      "engineer" nobody's an engineer here. You're coders/programmers. "Engineer" is glorification. Like calling a garbage man a "refuse management specialist". Or a temp agency guy a "a recruitment consultant". 🥳. By this labelling system I'd be an elite, veteran director of software architecture. But my ego doesn't need it. Let's just be coders and have some humility. This goes out to all you Vice Presidents of Digital Solutions and Senior Prime Ministers of Imagineering. Grow up.

    • @quickkcare605
      @quickkcare605 Рік тому

      @@endoflevelboss Bro everyone is saying that in a general manner. Everyone refers to it this way. No one asked for your dumb yet useless explanation!

    • @Knightfall23
      @Knightfall23 Рік тому +2

      @@endoflevelboss lol some people have actual degrees, masters, PhDs and accreditations in some sort of field of in engineering.
      We have every right to be called engineers as we don’t only just write “code”.
      Your expected to engineer technological solutions to solve for the businesses needs. Of course if you aren’t doing that and just writing a bunch of divs and if else logic your just a software developer yes.

  • @checksum00
    @checksum00 Рік тому +6

    You always learn something, even if the videos doesn't teach you anything directly. I had aboslutely no idea ctrl+shift+r would refresh without cache! That's literally a life saver.

  • @trjblq
    @trjblq Рік тому +6

    I found this interesting as a DevOps engineer who is training in DevSecOps. Another risk to mitigate. As always, thanks for the brilliant content!

  • @shayarand
    @shayarand Рік тому +2

    Great Video! I really like this CI/CD series. please keep them coming

  • @namantalati8243
    @namantalati8243 Рік тому

    Awesome💯 I am enjoying the CI/CD Series eagerly waiting for your next video

  • @abhaykush
    @abhaykush Рік тому

    sending love ♥

  • @seanvinsick
    @seanvinsick Рік тому +1

    You must be new to runners but you still have some good knowlege. Nice video! Btw in bash || is the action executed if errno is non zero. Basically it stops the runner from failing if make fails, if nonzero returned execute true. Pipeline won't crash.

  • @surkewrasoul4711
    @surkewrasoul4711 Рік тому +8

    Awesome video as usual, And since hardly anyone can spread the love of cyber security like you do, Is there any chance you can create a video on how to get rid of your presence on the compromised system and logs, avoiding the forensics detection or just bury the evidence of having been on the system and all that? Would be incredibly useful for new comers and those who are searching for some quality content from a believable source. Love and peace brother hammond, You are the best at what you do.

  • @germcauliffe7
    @germcauliffe7 Рік тому

    Fantastic Eductional video once again John. Keep up the great work !!!

  • @f2rv
    @f2rv Рік тому

    Great video John! You’re the best !

  • @syedshayanshah2729
    @syedshayanshah2729 Рік тому

    yeah john im enjoying your series of DevSecops love to see more content like this ci/cd pentesting and devsecops keep it up 👍👍👍

  • @TheClassyHacker
    @TheClassyHacker Рік тому

    Thank you for this video, super helpful for testing.

  • @gilbertsabina4944
    @gilbertsabina4944 Рік тому

    Awesome

  • @deadbeef2482
    @deadbeef2482 Рік тому

    wow, awesome!

  • @bejgli3278
    @bejgli3278 Рік тому

    Amazing vid

  • @juliocesaralvaroncal4434
    @juliocesaralvaroncal4434 Рік тому

    Afrontar los problemas es mejor que huir o esconderse tenga los resultados que tenga

  • @sTrenat
    @sTrenat Рік тому +1

    Regarding protected repo, I think task description was trying to be clear that your jenkins file is protected, and we need to modify application repo :)

  • @ceebee105
    @ceebee105 Рік тому

    I could be wrong but you should be able to determine write access on the repo if there is a little edit 🖋 icon near the download button then you have access... maybe?

  • @uveysyakut
    @uveysyakut Рік тому

    you are amazing 💯

  • @jbit590
    @jbit590 Рік тому

    Amazing video as always 😂 I signed up for snyk as well 👍 thank you very much 😊

    • @_JohnHammond
      @_JohnHammond  Рік тому +3

      YAAAASSS THANK YOU FOR JUMPING INTO SNYK!!

    • @jbit590
      @jbit590 Рік тому

      The urge to learn more haha I couldn't pass it up thank you, Love your content as I am just venturing over to cybersecurity your videos are very educational and easy to watch

  • @jesussandoval842
    @jesussandoval842 Рік тому

    Have you tried using set -x ? It will run the script, you will see the output of the script and the commands being executed.
    You can use set -o to shut that off as well.

  • @DannyakaITOOKADUMP
    @DannyakaITOOKADUMP Рік тому

    First! Haha love your videos John!

  • @onthewaytechtravel
    @onthewaytechtravel Рік тому

    Amazing..

  • @lakshyadutt5206
    @lakshyadutt5206 3 місяці тому

    This is fun

  • @SeriousGamer42
    @SeriousGamer42 Рік тому

    What tools do you advise beginners to use?

  • @logiciananimal
    @logiciananimal Рік тому

    I am not sure there *is* a way to tell for sure if branch protection is on.

  • @shpockboss3834
    @shpockboss3834 Рік тому

    How to find such issue for a bug bounty programs

  • @phillipnunes86
    @phillipnunes86 Рік тому

    And how do we solve or avoid this issue?

  • @Basieeee
    @Basieeee Рік тому

    I liek it

  • @seanvinsick
    @seanvinsick Рік тому

    It really is a headache when a new dev or inexperienced cicd dev joins the team, because you're constantly seeing commits for this kind of stuff.

  • @PoliticalPanic
    @PoliticalPanic Рік тому

    what the hell he just did ?