HackTheBox CA CTF - Using Snyk to Find & Fix Vulnerabilities

HackTheBox CA CTF - Using Snyk to Find & Fix Vulnerabilities

John Hammond

3 года назад

33,258 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@1anre
@1anre - 31.03.2023 17:23

This was both refreshing and humbling.

Didn’t know such easy-to-learn tools to get into the AppSec space even existed or were this accessible.

Would be great to see videos on your Career, how you knew Security was for you, & what you do to keep up to date with the latest trends in this Space.

Ответить
@vladostema
@vladostema - 12.11.2022 10:54

We need some kind of script that scans real url and find how to hack it

Ответить
@djorngougenhimer7455
@djorngougenhimer7455 - 18.06.2022 06:03

Have to give it a dislike as you don't say it's a paid promotion/sponsored video till the end, basically an advertisement.

Makes you look dodgy/questionable/untrustworthy

Have seen a couple (read 2 or 3) your other videos and they were interesting, but this make me question your integrity.

Ответить
@Bananananamann
@Bananananamann - 07.01.2022 12:09

Now add backwards compatibility to the mix!

I see how this could work in a CI/CD context on new apps though.

Ответить
@mk_r4zy450
@mk_r4zy450 - 03.08.2021 17:11

what application launcher are you using? :)

Ответить
@jorisschepers85
@jorisschepers85 - 14.07.2021 17:14

Could you use this in a King of the Hill to hold off the others?

Ответить
@shabnashummer645
@shabnashummer645 - 12.06.2021 10:33

Thanks John , You make me realize how vulnerable the apps we have developed . We were only focusing on the end-user requirement .

Ответить
@SONGOKU-tl3ht
@SONGOKU-tl3ht - 10.06.2021 08:29

Tool is cool and all, but mention "includes paid promotion"

Ответить
@BlRaidX
@BlRaidX - 25.05.2021 10:43

You hit ignore on most of them.

Ответить
@logiciananimal
@logiciananimal - 21.05.2021 23:38

I'd love to see Snyk target Mutilidae or Juice Shop or one of those

Ответить
@rajarshibasak559
@rajarshibasak559 - 21.05.2021 09:48

Bro, I am in depression after seeing your couple of videos.. So much I have to learn..I was thinking I know something about hacking, now it seems I know nothing😞

Ответить
@stephenmount6181
@stephenmount6181 - 18.05.2021 18:44

@John not to discredit Snyk and similar tools that I'm sure do more than check your dependency management (e.g. trying RCEs using libraries that are used like what they call ImageTragick), running `npm audit` and `npm audit fix` would capture what is in this video.

Ответить
@TomDoesTech
@TomDoesTech - 17.05.2021 01:27

I saw the thumbnail and thought "I need to see Ed Sheeran fixing vulnerabilities".

Ответить
@samoconnor3633
@samoconnor3633 - 15.05.2021 13:39

I'm literally making a web app vulnerability scanner right now for my a level NEA project wow 😂

Ответить
@psd00m
@psd00m - 15.05.2021 01:33

<3

Ответить
@DahlFreeman
@DahlFreeman - 15.05.2021 00:52

Dope!

Ответить
@rahulsharmar1
@rahulsharmar1 - 14.05.2021 09:21

Hey from where can i learn python scripting? like to automate tasks and make tools. can you suggest some good resources?

Ответить
@armandkruger911
@armandkruger911 - 14.05.2021 08:58

I cannot believe you have never heard of them. We have been using them for like 2 years

Ответить
@joshr9730
@joshr9730 - 14.05.2021 07:30

Diggin the shirt, I have one myself :D

Ответить
@Dedseq
@Dedseq - 14.05.2021 07:00

sick!

Ответить
@quentinh.9978
@quentinh.9978 - 14.05.2021 05:17

Don’t sub or like non music but love the video

Ответить
@michaelguier2053
@michaelguier2053 - 14.05.2021 03:32

yea synk is also incorporated into chromes dev tools.. if u run lighthouse tests it gens that report and refers u to snyk too good

Ответить
@JustFun-dj3pq
@JustFun-dj3pq - 14.05.2021 02:29

Super cool ! Great video as always bro

Ответить
@scarlett6761
@scarlett6761 - 14.05.2021 01:47

Don’t forget to register your copy of Sublime Text 😄

Ответить
@wilcosec
@wilcosec - 14.05.2021 00:23

Great ad, John! Thanks for putting this together. I hope they paid you BIG $$$ for that 1/2 hour ad.

Ответить
@kherkert
@kherkert - 13.05.2021 23:49

For next vid, please fix your mic settings. Listening through headset. Audio is clipping badly. Turn that gain down a bit 😉

Ответить
@lepsycho3691
@lepsycho3691 - 13.05.2021 22:34

I would have prefer you to disclose the sponsorship at beginning of the video not at 20 seconds from the end.

Otherwise great demo and a lot of potential from using snyk for CTF!

Ответить
@kopuz.co.uk.
@kopuz.co.uk. - 13.05.2021 21:02

lol "The BESTest todo app "evar"

Ответить
@PermisSecurity
@PermisSecurity - 13.05.2021 20:53

ippsec vs john Hammond pls

Ответить
@ArthursHD
@ArthursHD - 13.05.2021 19:14

Nice!

Ответить
@droidsino8072
@droidsino8072 - 13.05.2021 19:01

Thank you for everything you do 😊

Ответить
@MrFontaineInc
@MrFontaineInc - 13.05.2021 18:45

This is definitely a legit tool!! I hope to see more iterations of this in the future as the importance of "shifting left" becomes the norm.

Ответить
@OK_NOK
@OK_NOK - 13.05.2021 18:42

KOTH Nuke button

Ответить
@kbharathi1183
@kbharathi1183 - 13.05.2021 18:05

Sir is there any giveaway

Ответить
@SirHackaL0t.
@SirHackaL0t. - 13.05.2021 17:18

I enjoy your videos but your mic is either too close to your mouth or the signal is a bit hot causing distortion. :)

Ответить
@mossdem
@mossdem - 13.05.2021 16:41

Wow Snyk is awesome! What a great idea for security programs for startups and projects and even better it’s open-source !

Ответить
@georgesotiriadis2763
@georgesotiriadis2763 - 13.05.2021 16:41

Amazing video again john. I have a question in order to understand all that kind of web attacks is it better to know the technology like building a node app or php app and see why the vulnerability existed in first place? Like No sql injection etc.

Ответить
@0dayCTF
@0dayCTF - 13.05.2021 16:34

SNYK is OP ❤️

Ответить
@ventordicissimo
@ventordicissimo - 13.05.2021 16:07

Very interesting topic. I have to say tho, the audio is a bit clippy

Ответить
@dajiru1976
@dajiru1976 - 13.05.2021 14:48

Thanks to this guy I put my hands on keyboard, Learning all nights a bit of hacking. Thanks John.

Ответить
@VivekSingh-ve5pr
@VivekSingh-ve5pr - 13.05.2021 14:06

Thanks for bringing up super cool videos frequently. i'm always excited to watch them out

Ответить
@whoamisecurity9586
@whoamisecurity9586 - 13.05.2021 11:46

Hello 👋

Ответить
@oldGoatMilk
@oldGoatMilk - 13.05.2021 06:54

It premieres at 3am for me I have to watch it when I wake up.

Ответить