CI/CD GOAT: Mad Hatter Capture The Flag

Поділитися
Вставка
  • Опубліковано 15 вер 2024
  • jh.live/snykct... || Learn the ropes for Capture the Flag challenges and categories with Snyk's live CTF 101 workshop on March 30th, 2023! jh.live/snykct...
    🔥 UA-cam ALGORITHM ➡ Like, Comment, & Subscribe!
    🙏 SUPPORT THE CHANNEL ➡ jh.live/patreon
    🤝 SPONSOR THE CHANNEL ➡ jh.live/sponsor
    🌎 FOLLOW ME EVERYWHERE ➡ jh.live/discord ↔ jh.live/twitter ↔ jh.live/linkedin ↔ jh.live/instagram ↔ jh.live/tiktok
    💥 SEND ME MALWARE ➡ jh.live/malware

КОМЕНТАРІ • 39

  • @ahmerkhan496
    @ahmerkhan496 Рік тому +40

    Man you are insane, I am working as a Devops Engineer and this has some unique insights, keep up the good work !

    • @Knightfall23
      @Knightfall23 Рік тому +2

      This was nothing more than someone just running printenv within a script.
      If your a devops engineer you should know about the Solar Winds hacks that happened a few years ago, those were the real CI/CD and supply chain poisoning tactics.

    • @quickkcare605
      @quickkcare605 Рік тому +2

      @@Knightfall23 Yeah you are right bro. That guy must be an intern

    • @endoflevelboss
      @endoflevelboss Рік тому

      "engineer" nobody's an engineer here. You're coders/programmers. "Engineer" is glorification. Like calling a garbage man a "refuse management specialist". Or a temp agency guy a "a recruitment consultant". 🥳. By this labelling system I'd be an elite, veteran director of software architecture. But my ego doesn't need it. Let's just be coders and have some humility. This goes out to all you Vice Presidents of Digital Solutions and Senior Prime Ministers of Imagineering. Grow up.

    • @quickkcare605
      @quickkcare605 Рік тому

      @@endoflevelboss Bro everyone is saying that in a general manner. Everyone refers to it this way. No one asked for your dumb yet useless explanation!

    • @Knightfall23
      @Knightfall23 Рік тому +2

      @@endoflevelboss lol some people have actual degrees, masters, PhDs and accreditations in some sort of field of in engineering.
      We have every right to be called engineers as we don’t only just write “code”.
      Your expected to engineer technological solutions to solve for the businesses needs. Of course if you aren’t doing that and just writing a bunch of divs and if else logic your just a software developer yes.

  • @checksum00
    @checksum00 Рік тому +6

    You always learn something, even if the videos doesn't teach you anything directly. I had aboslutely no idea ctrl+shift+r would refresh without cache! That's literally a life saver.

  • @trjblq
    @trjblq Рік тому +6

    I found this interesting as a DevOps engineer who is training in DevSecOps. Another risk to mitigate. As always, thanks for the brilliant content!

  • @shayarand
    @shayarand Рік тому +2

    Great Video! I really like this CI/CD series. please keep them coming

  • @surkewrasoul4711
    @surkewrasoul4711 Рік тому +8

    Awesome video as usual, And since hardly anyone can spread the love of cyber security like you do, Is there any chance you can create a video on how to get rid of your presence on the compromised system and logs, avoiding the forensics detection or just bury the evidence of having been on the system and all that? Would be incredibly useful for new comers and those who are searching for some quality content from a believable source. Love and peace brother hammond, You are the best at what you do.

  • @abhaykush
    @abhaykush Рік тому

    sending love ♥

  • @namantalati8243
    @namantalati8243 Рік тому

    Awesome💯 I am enjoying the CI/CD Series eagerly waiting for your next video

  • @germcauliffe7
    @germcauliffe7 Рік тому

    Fantastic Eductional video once again John. Keep up the great work !!!

  • @syedshayanshah2729
    @syedshayanshah2729 Рік тому

    yeah john im enjoying your series of DevSecops love to see more content like this ci/cd pentesting and devsecops keep it up 👍👍👍

  • @seanvinsick5271
    @seanvinsick5271 Рік тому +1

    You must be new to runners but you still have some good knowlege. Nice video! Btw in bash || is the action executed if errno is non zero. Basically it stops the runner from failing if make fails, if nonzero returned execute true. Pipeline won't crash.

  • @gilbertsabina4944
    @gilbertsabina4944 Рік тому

    Awesome

  • @f2rv
    @f2rv Рік тому

    Great video John! You’re the best !

  • @sTrenat
    @sTrenat Рік тому +1

    Regarding protected repo, I think task description was trying to be clear that your jenkins file is protected, and we need to modify application repo :)

  • @TheClassyHacker
    @TheClassyHacker Рік тому

    Thank you for this video, super helpful for testing.

  • @juliocesaralvaroncal4434
    @juliocesaralvaroncal4434 Рік тому

    Afrontar los problemas es mejor que huir o esconderse tenga los resultados que tenga

  • @bejgli3278
    @bejgli3278 Рік тому

    Amazing vid

  • @deadbeef2482
    @deadbeef2482 Рік тому

    wow, awesome!

  • @jesussandoval842
    @jesussandoval842 Рік тому

    Have you tried using set -x ? It will run the script, you will see the output of the script and the commands being executed.
    You can use set -o to shut that off as well.

  • @ceebee105
    @ceebee105 Рік тому

    I could be wrong but you should be able to determine write access on the repo if there is a little edit 🖋 icon near the download button then you have access... maybe?

  • @jbit590
    @jbit590 Рік тому

    Amazing video as always 😂 I signed up for snyk as well 👍 thank you very much 😊

    • @_JohnHammond
      @_JohnHammond  Рік тому +3

      YAAAASSS THANK YOU FOR JUMPING INTO SNYK!!

    • @jbit590
      @jbit590 Рік тому

      The urge to learn more haha I couldn't pass it up thank you, Love your content as I am just venturing over to cybersecurity your videos are very educational and easy to watch

  • @lakshyadutt5206
    @lakshyadutt5206 22 дні тому

    This is fun

  • @uveysyakut
    @uveysyakut Рік тому

    you are amazing 💯

  • @onthewaytechtravel
    @onthewaytechtravel Рік тому

    Amazing..

  • @DannyakaITOOKADUMP
    @DannyakaITOOKADUMP Рік тому

    First! Haha love your videos John!

  • @logiciananimal
    @logiciananimal Рік тому

    I am not sure there *is* a way to tell for sure if branch protection is on.

  • @SeriousGamer42
    @SeriousGamer42 Рік тому

    What tools do you advise beginners to use?

  • @shpockboss3834
    @shpockboss3834 Рік тому

    How to find such issue for a bug bounty programs

  • @phillipnunes86
    @phillipnunes86 Рік тому

    And how do we solve or avoid this issue?

  • @Basieeee
    @Basieeee Рік тому

    I liek it

  • @seanvinsick5271
    @seanvinsick5271 Рік тому

    It really is a headache when a new dev or inexperienced cicd dev joins the team, because you're constantly seeing commits for this kind of stuff.

  • @PoliticalPanic
    @PoliticalPanic Рік тому

    what the hell he just did ?