How’d you find the course
Common Vulnerability Enumerations
It’s really important that the security community works together
can you find them?
me lol (it’s not a pub-key…)
maybe check your old projects to see if you’ve made similar dumb mistakes?
Ā
dependency stuffs
Trusting code we didn’t write ourselves
log4j (2 billion devices!!!)
pac-resolver (3 million weekly downloads)
npm install xyz
xyz
xyz
pip install falsk
falsk
:I don’t have an example 🤷
keeping it secure
.gitignore
.env
.git
basically just ~secrets~
Browsing vs SDN (site-to-site)
“providers who claim not to keep any logs of their users’ online activities recently left 1.2 terabytes of private user data exposed” 🤔
what to do once you have RCE
www-data
or Nobody
)