Главная
Study mode:
on
1
Intro
2
Stack Exchange
3
Software Deployment
4
Trust
5
Dependencies
6
Repository Provider
7
Cloud Provider
8
Its All Software
9
Colonel Bashing
10
Other options
11
Attackers viewpoint
12
Rule 34 of security
13
Short Con
14
Get The Code
15
Root Shell
16
Choosing A Target
17
Push A New Version
18
Access Control
19
Lack of curation
20
Lack of digital signing
21
Linux repositories
22
Darker files
23
Profit Chels
24
Metasploit
25
Audit The Code
26
Metasploit Packages
27
Trusted Repository
28
Better Repository Security
29
Update Framework
30
Long Con
31
Open Source Libraries
32
Start Your Own Package Repository
33
If I Was A Bad Guy
34
Fixing This
35
Problem
36
Module Count
37
Python
38
Conclusion
39
Questions
Description:
Watch a conference talk from AppSecEU 2015 in Amsterdam where Rory Mccune discusses security challenges in modern software deployment. Explore topics like trust issues with dependencies, repository providers, and cloud services. Learn about potential attack vectors, including pushing malicious code versions and exploiting weak access controls. Examine strategies for improving repository security, such as digital signing and better curation. Gain insights into the risks of open-source libraries and the importance of auditing code. Discover practical tips for securing software deployment processes and mitigating vulnerabilities in the modern development ecosystem.

Security and Modern Software Deployment - AppSec EU 2015

OWASP Foundation
Add to list
0:00 / 0:00