Repo Jacking - How Github Usernames Expose Projects to RCE

Repo Jacking - How Github Usernames Expose Projects to RCE

NorthSec via YouTube Direct link

Intro

1 of 14

1 of 14

Intro

Class Central Classrooms beta

YouTube playlists curated by Class Central.

Classroom Contents

Repo Jacking - How Github Usernames Expose Projects to RCE

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Intro
  2. 2 Open-source Supply Chain Attacks
  3. 3 Repo Jacking
  4. 4 Vulnerable Scenarios
  5. 5 Repository Redirects
  6. 6 GitHub's Response
  7. 7 Mass Analysis
  8. 8 Data Collection
  9. 9 Clean Up
  10. 10 Hijackable Usernames
  11. 11 Dependency Analysis
  12. 12 4. Directly Vulnerable Projects
  13. 13 Key Findings
  14. 14 Remediations

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.