Loading…
LASCON 2014 has ended
View analytic
Thursday, October 23 • 4:00pm - 4:45pm
Is this your pipe? Hijacking the build pipeline

Sign up or log in to save this to your schedule and see who's attending!

As developers of the web, we rely on tools to automate building code, run tests, and even deploy services. What happens when we're too trusting of CI/CD pipelines? Credentials get exposed, hijacked, and re-purposed. We'll talk about how often and what happens when people leak public cloud credentials, how some are protecting themselves using encrypted secrets, how to bypass protections against leaking decrypted secrets and how to turn their Jenkins into your own butler. Come hijack credentials out of repositories, steal hidden and encrypted secrets using builds, and hijack infrastructure via their continuous deployment. 


Speakers
avatar for Greg Anderson

Greg Anderson

Founder, Infinitiv


Thursday October 23, 2014 4:00pm - 4:45pm
Pecan Room Norris Conference Center, http://lascon.org/venue/

Attendees (0)